PT-2025-44112 · Linux+4 · Linux Kernel+4

Published

2025-09-22

·

Updated

2026-05-07

·

CVE-2025-40044

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc4-syzkaller-00261-g850925a8133c
Description The Linux kernel contains a flaw within the UDF filesystem implementation. Specifically, the handling of Allocation Extent Descriptors lacks proper validation of the lengthAllocDescs value against the block size. This can lead to a buffer over-read when parsing corrupted or crafted images, potentially triggering a use-after-free read condition via the crc itu t() function. The issue was discovered by the Linux Verification Center using Syzkaller. The vulnerability occurs when parsing Allocation Extent Descriptor, where lengthAllocDescs comes from on-disk data and must be validated against the block size.
Recommendations Update to version 6.12.0-rc4-syzkaller-00261-g850925a8133c or later.

Exploit

Fix

Use After Free

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-68843
BDU:2025-13779
CVE-2025-40044
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-CA66-1133-C23F
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2632
OESA-2025-2636
OESA-2025-2656
OESA-2025-2657
OESA-2025-2658
OESA-2025-2659
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4111-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4320-1
SUSE-SU-2026:0474-1
SUSE-SU-2026:0496-1
SUSE-SU-2026:0617-1
SUSE-SU-2026:1131-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu