CVE-2025-40302 — Out-of-bounds Write in Linux
Severity
6.3MEDIUM
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
media: videobuf2: forbid remove_bufs when legacy fileio is active
vb2_ioctl_remove_bufs() call manipulates queue internal buffer list,
potentially overwriting some pointers used by the legacy fileio access
mode. Forbid that ioctl when fileio is active to protect internal queue
state between subsequent read/write calls.
Affected Packages5 packages
▶CVEListV5linux/linuxa3293a85381ec9680aa2929547fbc76c5d87a1b2 — a6a493b985bfffac097a4e1be09f98b27729dca8+3