PT-2025-42777 · Linux+3 · Linux Kernel+3

Published

2025-09-11

·

Updated

2026-05-07

·

CVE-2025-40008

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc3
Description A flaw exists in the Linux kernel related to out-of-bounds access to shadow memory within the Kernel Memory Sanitizer (KMSAN). Specifically, when running sha224 kunit on a KMSAN-enabled kernel, a crash occurs in kmsan internal set shadow origin(). This is triggered when memset() is called on a buffer that is not 4-byte aligned and extends to the end of a guard page. The root cause is an incorrect calculation of shadow memory addresses within the kmsan internal set shadow origin() function, leading to reads from unmapped shadow memory. The function kmsan internal set shadow origin() is involved in the process.
Recommendations Update to a version of the Linux kernel greater than or equal to 6.17.0-rc3.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13574
CVE-2025-40008
DLA-4379-1
DSA-6053-1
ECHO-FC08-79C1-3E6B
MGASA-2025-0309
MGASA-2025-0310
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu