CVE-2025-40063 — Linux vulnerability
Severity
6.1MEDIUM
No vectorEPSS
0.0%
top 92.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: comp - Use same definition of context alloc and free ops
In commit 42d9f6c77479 ("crypto: acomp - Move scomp stream allocation
code into acomp"), the crypto_acomp_streams struct was made to rely on
having the alloc_ctx and free_ctx operations defined in the same order
as the scomp_alg struct. But in that same commit, the alloc_ctx and
free_ctx members of scomp_alg may be randomized by structure layout
randomization, si…
Affected Packages5 packages
▶CVEListV5linux/linux42d9f6c774790d290c175e8775ce9f1366438098 — 779d3b6f2d32c5f1da6163e959abe1e1ffe2945b+2