CVE-2025-40364
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.27% probability · 20th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/233b210a678bddf8b49b02a070074a52b87e6d43Patch
- https://git.kernel.org/stable/c/35ae7910c349fb3c60439992e2e0e79061e95382Patch
- https://git.kernel.org/stable/c/a1b17713b32c75a90132ea2f92b1257f3bbc20f3Patch
- https://git.kernel.org/stable/c/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3Patch
- https://git.kernel.org/stable/c/b86f1d51731e621e83305dc9564ae14c9ef752bfPatch
- https://git.kernel.org/stable/c/d63b0e8a628e62ca85a0f7915230186bb92f8bb4Patch
- https://git.kernel.org/stable/c/f0ef94553868d07c1b14d7743a7e2553e5a831a3Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.