CVE-2025-40270 — Use After Free in Linux
Severity
5.8MEDIUM
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
mm, swap: fix potential UAF issue for VMA readahead
Since commit 78524b05f1a3 ("mm, swap: avoid redundant swap device
pinning"), the common helper for allocating and preparing a folio in the
swap cache layer no longer tries to get a swap device reference
internally, because all callers of __read_swap_cache_async are already
holding a swap entry reference. The repeated swap device pinning isn't
needed on the same swap device.
…
Affected Packages5 packages
▶CVEListV5linux/linux78524b05f1a3e16a5d00cc9c6259c41a9d6003ce — a4145be7b56bfa87dce56415c3ad993071462b8a+2