cbcvebase.
CVE-2025-40291
published 2025-12-08

CVE-2025-40291: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix regbuf vector size truncation There is a report of io_estimate_bvec_size()…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix regbuf vector size truncation There is a report of io_estimate_bvec_size() truncating the calculated number of segments that leads to corruption issues. Check it doesn't overflow "int"s used later. Rough but simple, can be improved on top.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 9ef4cbbcb4ac3786a1a4164507511b76b2a572c5 < 826ce37a842633efe1bb763e4b13045d74060d72826ce37a842633efe1bb763e4b13045d74060d72
linuxlinux>= 9ef4cbbcb4ac3786a1a4164507511b76b2a572c5 < 146eb58629f45f8297e83d69e64d4eea4b28d972146eb58629f45f8297e83d69e64d4eea4b28d972
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.15.0 < 6.17.86.17.8
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.