CVE-2025-40143 — Linux vulnerability
15 documents6 sources
Severity
—N/A
No vectorEPSS
0.0%
top 93.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: dont report verifier bug for missing bpf_scc_visit on speculative path
Syzbot generated a program that triggers a verifier_bug() call in
maybe_exit_scc(). maybe_exit_scc() assumes that, when called for a
state with insn_idx in some SCC, there should be an instance of struct
bpf_scc_visit allocated for that SCC. Turns out the assumption does
not hold for speculative execution paths. See example in the next
patch.
maybe_sc…
Affected Packages4 packages
▶CVEListV5linux/linuxc9e31900b54cadf5398dfb838c0a63effa1defec — 3861e7c4324aa20a632fb74eb3904114f6afdb57+2
🔴Vulnerability Details
8📋Vendor Advisories
6Red Hat
▶