CVE-2025-40216
published 2025-12-04CVE-2025-40216: In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignment for user pointers, however the
calculation of an offset of the first page into a folio after coalescing
uses some weird bit mask logic, get rid of it.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.12.37-1 (forky) | linux 6.12.37-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= a8edbb424b1391b077407c75d8f5d2ede77aa70d < 50998b0ae7d9d552e96d8b7239981cf05f65eff5 | 50998b0ae7d9d552e96d8b7239981cf05f65eff5 |
| linux | linux | >= a8edbb424b1391b077407c75d8f5d2ede77aa70d < f16769241594be59387b56ab525e327f54377e60 | f16769241594be59387b56ab525e327f54377e60 |
| linux | linux | >= a8edbb424b1391b077407c75d8f5d2ede77aa70d < 3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b | 3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b |
| linux | linux_kernel | >= 0 < 6.12.37-1 | 6.12.37-1 |
| linux | linux_kernel | >= 0 < 6.12.37-1 | 6.12.37-1 |
| linux | linux_kernel | >= 6.12.0 < 6.12.36 | 6.12.36 |
| linux | linux_kernel | >= 6.13.0 < 6.15.5 | 6.15.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: io_uring/rsrc: don't rely on user vaddr alignment
vendor_redhat·2025-12-04·CVSS 7.0
CVE-2025-40216 [MEDIUM] kernel: io_uring/rsrc: don't rely on user vaddr alignment
kernel: io_uring/rsrc: don't rely on user vaddr alignment
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignment for user pointers, however the
calculation of an offset of the first page into a folio after coalescing
uses some weird bit mask logic, get rid of it.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: ker
Debian
CVE-2025-40216: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/rs...
vendor_debian·2025
CVE-2025-40216 [LOW] CVE-2025-40216: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/rs...
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, however the calculation of an offset of the first page into a folio after coalescing uses some weird bit mask logic, get rid of it.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.12.37-1)
sid: resolved (fixed in 6.12.37-1)
trixie: resolved (fixed in 6.12.37-1)
GHSA
GHSA-vv4p-ph8q-2hhx: In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignme
ghsa_unreviewed·2025-12-04
CVE-2025-40216 GHSA-vv4p-ph8q-2hhx: In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignme
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignment for user pointers, however the
calculation of an offset of the first page into a folio after coalescing
uses some weird bit mask logic, get rid of it.
OSV
io_uring/rsrc: don't rely on user vaddr alignment
osv·2025-12-04
CVE-2025-40216 io_uring/rsrc: don't rely on user vaddr alignment
io_uring/rsrc: don't rely on user vaddr alignment
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rsrc: don't rely on user vaddr alignment
There is no guaranteed alignment for user pointers, however the
calculation of an offset of the first page into a folio after coalescing
uses some weird bit mask logic, get rid of it.
OSV
CVE-2025-40216: In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment
osv·2025-12-04
CVE-2025-40216 CVE-2025-40216: In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, however the calculation of an offset of the first page into a folio after coalescing uses some weird bit mask logic, get rid of it.
No detection rules found.
No public exploits indexed.
2025-12-04
Published