cbcvebase.
CVE-2025-40364
published 2025-04-18

CVE-2025-40364: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.6th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < 233b210a678bddf8b49b02a070074a52b87e6d43233b210a678bddf8b49b02a070074a52b87e6d43
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < a1b17713b32c75a90132ea2f92b1257f3bbc20f3a1b17713b32c75a90132ea2f92b1257f3bbc20f3
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < b86f1d51731e621e83305dc9564ae14c9ef752bfb86f1d51731e621e83305dc9564ae14c9ef752bf
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < 35ae7910c349fb3c60439992e2e0e79061e9538235ae7910c349fb3c60439992e2e0e79061e95382
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < f0ef94553868d07c1b14d7743a7e2553e5a831a3f0ef94553868d07c1b14d7743a7e2553e5a831a3
linuxlinux>= c7fb19428d67dd0a2a78a4f237af01d39c78dc5a < d63b0e8a628e62ca85a0f7915230186bb92f8bb4d63b0e8a628e62ca85a0f7915230186bb92f8bb4
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 5.19 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.2 < 6.6.786.6.78
linuxlinux_kernel>= 6.7 < 6.12.146.12.14

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.