cbcvebase.
CVE-2025-40126
published 2025-11-12

CVE-2025-40126: In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC The…

PriorityP421high7.8
EPSS
0.22%
12.1th percentile
In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC The referenced commit introduced exception handlers on user-space memory references in copy_from_user and copy_to_user. These handlers return from the respective function and calculate the remaining bytes left to copy using the current register contents. This commit fixes a couple of bad calculations. This will fix the return value of copy_from_user and copy_to_user in the faulting case. The behaviour of memcpy stays unchanged.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.4.34 < 4.54.5
linuxlinux>= 4.8.10 < 4.94.9
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 0bf3dc3a2156f1c5ddaba4b85d097678746341140bf3dc3a2156f1c5ddaba4b85d09767874634114
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 41c18baee66134e6ef786eb075c1b6adb22432b041c18baee66134e6ef786eb075c1b6adb22432b0
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 59424dc0d0e044b2eb007686a4724ddd91d57db559424dc0d0e044b2eb007686a4724ddd91d57db5
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 9b137f277cc3297044aabd950f589e505d30104c9b137f277cc3297044aabd950f589e505d30104c
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 674ff598148a28bae0b5372339de56f2abf0b1d1674ff598148a28bae0b5372339de56f2abf0b1d1
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 7de3a75bbc8465d816336c74d50109e73501efab7de3a75bbc8465d816336c74d50109e73501efab
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 57c278500fce3cd4e1c540700c0b05426a95839357c278500fce3cd4e1c540700c0b05426a958393
linuxlinux>= cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada < 4fba1713001195e59cfc001ff1f2837dab877efb4fba1713001195e59cfc001ff1f2837dab877efb
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.9.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.