cbcvebase.
CVE-2025-40311
published 2025-12-08

CVE-2025-40311: In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When IOMMU is…

PriorityP420high7.8
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When IOMMU is enabled, dma_alloc_coherent() with GFP_USER may return addresses from the vmalloc range. If such an address is mapped without VM_MIXEDMAP, vm_insert_page() will trigger a BUG_ON due to the VM_PFNMAP restriction. Fix this by checking for vmalloc addresses and setting VM_MIXEDMAP in the VMA before mapping. This ensures safe mapping and avoids kernel crashes. The memory is still driver-allocated and cannot be accessed directly by userspace.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= ac0ae6a96aa58eeba4aed97b12ef1dea8c5bf399 < 7ec8ac9f73d4a9438c2186768d6de27ace37531e7ec8ac9f73d4a9438c2186768d6de27ace37531e
linuxlinux>= ac0ae6a96aa58eeba4aed97b12ef1dea8c5bf399 < d1dfe21a332d38a6a09658ec29a55940afb5fe36d1dfe21a332d38a6a09658ec29a55940afb5fe36
linuxlinux>= ac0ae6a96aa58eeba4aed97b12ef1dea8c5bf399 < 73c7c2cdb442fc4160d2a2a4bfffbd162af06cb973c7c2cdb442fc4160d2a2a4bfffbd162af06cb9
linuxlinux>= ac0ae6a96aa58eeba4aed97b12ef1dea8c5bf399 < 513024d5a0e34fd34247043f1876b6138ca52847513024d5a0e34fd34247043f1876b6138ca52847
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.8.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.