CVE-2025-40293 — Integer Overflow or Wraparound in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.1%
top 84.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Don't overflow during division for dirty tracking
If pgshift is 63 then BITS_PER_TYPE(*bitmap->bitmap) * pgsize will overflow
to 0 and this triggers divide by 0.
In this case the index should just be 0, so reorganize things to divide
by shift and avoid hitting any overflows.
Affected Packages7 packages
▶CVEListV5linux/linux58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 — 07105e61882ff4a7d58db63cc5f9e90c6c60506c+5