CVE-2025-40290 — Linux vulnerability
18 documents6 sources
Severity
7.2HIGHOSV
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 6
Description
In the Linux kernel, the following vulnerability has been resolved:
xsk: avoid data corruption on cq descriptor number
Since commit 30f241fcf52a ("xsk: Fix immature cq descriptor
production"), the descriptor number is stored in skb control block and
xsk_cq_submit_addr_locked() relies on it to put the umem addrs onto
pool's completion queue.
skb control block shouldn't be used for this purpose as after transmit
xsk doesn't have control over it and other subsystems could use it. This
leads to t…
Affected Packages5 packages
▶CVEListV5linux/linux30f241fcf52aaaef7ac16e66530faa11be78a865 — c5ea2e50b5c9aa80c5b53526257540f0c26cd66d+3