CVE-2025-40046 — Integer Overflow or Wraparound in Linux
Severity
5.4MEDIUM
No vectorEPSS
0.0%
top 92.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring/zcrx: fix overshooting recv limit
It's reported that sometimes a zcrx request can receive more than was
requested. It's caused by io_zcrx_recv_skb() adjusting desc->count for
all received buffers including frag lists, but then doing recursive
calls to process frag list skbs, which leads to desc->count double
accounting and underflow.
Affected Packages5 packages
▶CVEListV5linux/linux6699ec9a23f85f1764183430209c741847c45f12 — 8bcc9eaf1b19f1a7029cba19f6bd4122b40f6c4f+2
🔴Vulnerability Details
8📋Vendor Advisories
7Red Hat▶
org.apache.activemq/apache-activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-mqtt: MQTT control packet remaining length field is not properly validated (missing fix for CVE-2025↗2026-04-09
💬Community
1Bugzilla▶
CVE-2026-40046 org.apache.activemq/apache-activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-mqtt: MQTT control packet remaining length field is not properly validated (missing f↗2026-04-09