CVE-2025-40198 — Improper Null Termination in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 87.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
Unlike other strings in the ext4 superblock, we rely on tune2fs to
make sure s_mount_opts is NUL terminated. Harden
parse_apply_sb_mount_options() by treating s_mount_opts as a potential
__nonstring.
Affected Packages7 packages
▶CVEListV5linux/linux8b67f04ab9de5d8f3a71aef72bf02c995a506db5 — 7bf46ff83a0ef11836e38ebd72cdc5107209342d+7