cbcvebase.
CVE-2025-40046
published 2025-10-28

CVE-2025-40046: In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix overshooting recv limit It's reported that sometimes a zcrx request can…

PriorityP342high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.33%
25.0th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix overshooting recv limit It's reported that sometimes a zcrx request can receive more than was requested. It's caused by io_zcrx_recv_skb() adjusting desc->count for all received buffers including frag lists, but then doing recursive calls to process frag list skbs, which leads to desc->count double accounting and underflow.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 6699ec9a23f85f1764183430209c741847c45f12 < 8bcc9eaf1b19f1a7029cba19f6bd4122b40f6c4f8bcc9eaf1b19f1a7029cba19f6bd4122b40f6c4f
linuxlinux>= 6699ec9a23f85f1764183430209c741847c45f12 < 09cfd3c52ea76f43b3cb15e570aeddf633d65e8009cfd3c52ea76f43b3cb15e570aeddf633d65e80
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.15.0 < 6.17.36.17.3
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.