cbcvebase.
CVE-2025-40358
published 2025-12-16

CVE-2025-40358: In the Linux kernel, the following vulnerability has been resolved: riscv: stacktrace: Disable KASAN checks for non-current tasks Unwinding the stack of a task…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: stacktrace: Disable KASAN checks for non-current tasks Unwinding the stack of a task other than current, KASAN would report "BUG: KASAN: out-of-bounds in walk_stackframe+0x41c/0x460" There is a same issue on x86 and has been resolved by the commit 84936118bdf3 ("x86/unwind: Disable KASAN checks for non-current tasks") The solution could be applied to RISC-V too. This patch also can solve the issue: https://seclists.org/oss-sec/2025/q4/23 [[email protected]: clean up checkpatch issues]

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 5d8544e2d0075a5f3c9a2cf27152354d54360da1 < ef4d626ac59a56f8ec5cc09c1fef26f2923eec6fef4d626ac59a56f8ec5cc09c1fef26f2923eec6f
linuxlinux>= 5d8544e2d0075a5f3c9a2cf27152354d54360da1 < f34ba22989da61186f30a40b6a82e0b3337b96fcf34ba22989da61186f30a40b6a82e0b3337b96fc
linuxlinux>= 5d8544e2d0075a5f3c9a2cf27152354d54360da1 < 27379fcc15a10d3e3780fe79ba3fc7ed1ccd78e227379fcc15a10d3e3780fe79ba3fc7ed1ccd78e2
linuxlinux>= 5d8544e2d0075a5f3c9a2cf27152354d54360da1 < 2c8d2b53866fb229b438296526ef0fa5a990e5e52c8d2b53866fb229b438296526ef0fa5a990e5e5
linuxlinux>= 5d8544e2d0075a5f3c9a2cf27152354d54360da1 < 060ea84a484e852b52b938f234bf9b5503a6c910060ea84a484e852b52b938f234bf9b5503a6c910
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.15.0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.