CVE-2025-40291 — Integer Overflow or Wraparound in Linux
Severity
6.1MEDIUM
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix regbuf vector size truncation
There is a report of io_estimate_bvec_size() truncating the calculated
number of segments that leads to corruption issues. Check it doesn't
overflow "int"s used later. Rough but simple, can be improved on top.
Affected Packages5 packages
▶CVEListV5linux/linux9ef4cbbcb4ac3786a1a4164507511b76b2a572c5 — 826ce37a842633efe1bb763e4b13045d74060d72+2