CVE-2025-40364
published 2025-04-18CVE-2025-40364: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix io_req_prep_async with provided buffers
io_req_prep_async() can import provided buffers, commit the ring state
by giving up on that before, it'll be reimported later if needed.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.129-1 (bookworm) | linux 6.1.129-1 (bookworm) |
| chrome_chrome | — | — | |
| linux | linux | — | — |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < 233b210a678bddf8b49b02a070074a52b87e6d43 | 233b210a678bddf8b49b02a070074a52b87e6d43 |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < a1b17713b32c75a90132ea2f92b1257f3bbc20f3 | a1b17713b32c75a90132ea2f92b1257f3bbc20f3 |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < b86f1d51731e621e83305dc9564ae14c9ef752bf | b86f1d51731e621e83305dc9564ae14c9ef752bf |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3 | a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3 |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < 35ae7910c349fb3c60439992e2e0e79061e95382 | 35ae7910c349fb3c60439992e2e0e79061e95382 |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < f0ef94553868d07c1b14d7743a7e2553e5a831a3 | f0ef94553868d07c1b14d7743a7e2553e5a831a3 |
| linux | linux | >= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < d63b0e8a628e62ca85a0f7915230186bb92f8bb4 | d63b0e8a628e62ca85a0f7915230186bb92f8bb4 |
| linux | linux_kernel | >= 0 < 6.1.129-1 | 6.1.129-1 |
| linux | linux_kernel | >= 0 < 6.12.15-1 | 6.12.15-1 |
| linux | linux_kernel | >= 0 < 6.12.15-1 | 6.12.15-1 |
| linux | linux_kernel | >= 5.19 < 6.1.129 | 6.1.129 |
| linux | linux_kernel | >= 6.13 < 6.13.3 | 6.13.3 |
| linux | linux_kernel | >= 6.2 < 6.6.78 | 6.6.78 |
| linux | linux_kernel | >= 6.7 < 6.12.14 | 6.12.14 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24g7-95rm-cqcc: In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix io_req_prep_async with provided buffers
io_req_prep_async() can im
ghsa_unreviewed·2025-04-18
CVE-2025-40364 [HIGH] GHSA-24g7-95rm-cqcc: In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix io_req_prep_async with provided buffers
io_req_prep_async() can im
In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix io_req_prep_async with provided buffers
io_req_prep_async() can import provided buffers, commit the ring state
by giving up on that before, it'll be reimported later if needed.
OSV
CVE-2025-40364: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can impo
osv·2025-04-18·CVSS 7.8
CVE-2025-40364 [HIGH] CVE-2025-40364: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can impo
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-40364
vendor_chrome·2025-09-03·CVSS 7.8
CVE-2025-40364 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2025-40364
Long Term Support Channel Update for ChromeOS
CVE-2025-40364
Red Hat
kernel: io_uring: fix io_req_prep_async with provided buffers
vendor_redhat·2025-04-18·CVSS 7.8
CVE-2025-40364 [HIGH] CWE-401 kernel: io_uring: fix io_req_prep_async with provided buffers
kernel: io_uring: fix io_req_prep_async with provided buffers
In the Linux kernel, the following vulnerability has been resolved:
io_uring: fix io_req_prep_async with provided buffers
io_req_prep_async() can import provided buffers, commit the ring state
by giving up on that before, it'll be reimported later if needed.
Statement: No Red Hat products are affected by this flaw, as the io_uring subsystem is not enabled in any currently shipping kernel release. It could be enabled in latest versions of Red Hat Enterprise Linux only. The bug is about potential leak of memory and doesn't lead to any more severe security impact.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of us
Debian
CVE-2025-40364: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring: f...
vendor_debian·2025·CVSS 7.8
CVE-2025-40364 [HIGH] CVE-2025-40364: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring: f...
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
Scope: local
bookworm: resolved (fixed in 6.1.129-1)
bullseye: resolved
forky: resolved (fixed in 6.12.15-1)
sid: resolved (fixed in 6.12.15-1)
trixie: resolved (fixed in 6.12.15-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/233b210a678bddf8b49b02a070074a52b87e6d43https://git.kernel.org/stable/c/35ae7910c349fb3c60439992e2e0e79061e95382https://git.kernel.org/stable/c/a1b17713b32c75a90132ea2f92b1257f3bbc20f3https://git.kernel.org/stable/c/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3https://git.kernel.org/stable/c/b86f1d51731e621e83305dc9564ae14c9ef752bfhttps://git.kernel.org/stable/c/d63b0e8a628e62ca85a0f7915230186bb92f8bb4https://git.kernel.org/stable/c/f0ef94553868d07c1b14d7743a7e2553e5a831a3
2025-04-18
Published