cbcvebase.
CVE-2025-40259
published 2025-12-04

CVE-2025-40259: In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The…

PriorityP421high7.8
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.85 < 3.173.17
linuxlinux>= 3.18.101 < 3.193.19
linuxlinux>= 4.1.52 < 4.24.2
linuxlinux>= 4.4.123 < 4.54.5
linuxlinux>= 4.9.89 < 4.104.10
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < 11eeee00c94d770d4e45364060b5f1526dfe567b11eeee00c94d770d4e45364060b5f1526dfe567b
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < db6ac8703ab2b473e1ec845f57f6dd961a388d9fdb6ac8703ab2b473e1ec845f57f6dd961a388d9f
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < 109afbd88ecc46b6cc7551367222387e97999765109afbd88ecc46b6cc7551367222387e97999765
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < 3dfd520c3b4ffe69e0630c580717d40447ab842f3dfd520c3b4ffe69e0630c580717d40447ab842f
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < b343cee5df7e750d9033fba33e96fc4399fa88a5b343cee5df7e750d9033fba33e96fc4399fa88a5
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < b2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0fb2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0f
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < 6983d8375c040bb449d2187f4a57a20de01244fe6983d8375c040bb449d2187f4a57a20de01244fe
linuxlinux>= 97d27b0dd015e980ade63fda111fd1353276e28b < 90449f2d1e1f020835cba5417234636937dd657e90449f2d1e1f020835cba5417234636937dd657e
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat7.0MEDIUM
vendor_msrc6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.