cbcvebase.
CVE-2025-40051
published 2025-10-28

CVE-2025-40051: In the Linux kernel, the following vulnerability has been resolved: vhost: vringh: Modify the return value check The return value of copy_from_iter and…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: vhost: vringh: Modify the return value check The return value of copy_from_iter and copy_to_iter can't be negative, check whether the copied lengths are equal.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < db042925a5ab7a550b710addeadbf6f72e3a8a4bdb042925a5ab7a550b710addeadbf6f72e3a8a4b
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < 78dc7362662fedaa1928fb8e4f27401c8322905d78dc7362662fedaa1928fb8e4f27401c8322905d
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < baa37b1c7e29546f79c39bef0d18c4edc9f39bb1baa37b1c7e29546f79c39bef0d18c4edc9f39bb1
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < cfa0654402c06d086201a9ff167eb95da5844fc3cfa0654402c06d086201a9ff167eb95da5844fc3
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < 82a8d0fda55b35361ee7f35b54fa2b66d7847d2b82a8d0fda55b35361ee7f35b54fa2b66d7847d2b
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.0.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.