cbcvebase.
CVE-2025-40319
published 2025-12-08

CVE-2025-40319: In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work can be…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work can be queued in bpf_ringbuf_commit() but the ring buffer is freed before the work executes. In the syzbot reproducer, a BPF program attached to sched_switch triggers bpf_ringbuf_commit(), queuing an irq_work. If the ring buffer is freed before this work executes, the irq_work thread may accesses freed memory. Calling `irq_work_sync(&rb->work)` ensures that all pending irq_work complete before freeing the buffer.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < 47626748a2a00068dbbd5836d19076637b4e235b47626748a2a00068dbbd5836d19076637b4e235b
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < de2ce6b14bc3e565708a39bdba3ef9162aeffc72de2ce6b14bc3e565708a39bdba3ef9162aeffc72
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < e1828c7a8d8135e21ff6adaaa9458c32aae13b11e1828c7a8d8135e21ff6adaaa9458c32aae13b11
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < 6451141103547f4efd774e912418a3b4318046c66451141103547f4efd774e912418a3b4318046c6
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < 10ca3b2eec384628bc9f5d8190aed9427ad2dde610ca3b2eec384628bc9f5d8190aed9427ad2dde6
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < 430e15544f11f8de26b2b5109c7152f71b78295e430e15544f11f8de26b2b5109c7152f71b78295e
linuxlinux>= 457f44363a8894135c85b7a9afd2bd8196db24ab < 4e9077638301816a7d73fa1e1b4c1db4a7e3b59c4e9077638301816a7d73fa1e1b4c1db4a7e3b59c
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.8.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.