cbcvebase.
CVE-2025-40081
published 2025-10-28

CVE-2025-40081: In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() Cast nr_pages to unsigned long to avoid…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() Cast nr_pages to unsigned long to avoid overflow when handling large AUX buffer sizes (>= 2 GiB).

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 656e9a5d69acdd1b20462f4a33378b90ddcb9626656e9a5d69acdd1b20462f4a33378b90ddcb9626
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 9c045d4501f7f70724a3bbb561f4f22d292bbfe69c045d4501f7f70724a3bbb561f4f22d292bbfe6
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 5d01f2b81568289443d22f1e13a363f829de63435d01f2b81568289443d22f1e13a363f829de6343
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 7500384d3c9587593d75ded3b006835e7aa73ef87500384d3c9587593d75ded3b006835e7aa73ef8
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 379cae2cb982f571cda9493ac573ab71125fd299379cae2cb982f571cda9493ac573ab71125fd299
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < 1a19ba8e1f4ff24ece8ca69b79df8442c431db901a19ba8e1f4ff24ece8ca69b79df8442c431db90
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < e516cfd19b0f4c774a57b17fb43a7f41991f0735e516cfd19b0f4c774a57b17fb43a7f41991f0735
linuxlinux>= d5d9696b03808bc6be723cc85288c912c3a05606 < a29fea30dd93da16652930162b177941abd8c75ea29fea30dd93da16652930162b177941abd8c75e
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.15.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.