cbcvebase.
CVE-2025-40056
published 2025-10-28

CVE-2025-40056: In the Linux kernel, the following vulnerability has been resolved: vhost: vringh: Fix copy_to_iter return value check The return value of copy_to_iter can't…

PriorityP419high7.8
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: vhost: vringh: Fix copy_to_iter return value check The return value of copy_to_iter can't be negative, check whether the copied length is equal to the requested length instead of checking for negative values.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < bd71e7e0a612740e4de5524880c7cd40293af5f7bd71e7e0a612740e4de5524880c7cd40293af5f7
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < 781226e11d5bdea0d69c7b5aa3cda874093c73b8781226e11d5bdea0d69c7b5aa3cda874093c73b8
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < b3a950d236e98440c07405ba597b11bce56a8050b3a950d236e98440c07405ba597b11bce56a8050
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < 68aac2b335d474b938d154b9c95cbc58838cb2ce68aac2b335d474b938d154b9c95cbc58838cb2ce
linuxlinux>= 309bba39c945ac8ab8083ac05cd6cfe5822968e0 < 439263376c2c4e126cac0d07e4987568de4eaba5439263376c2c4e126cac0d07e4987568de4eaba5
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.0.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc5.5MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.