PT-2025-44133 · Linux+3 · Linux Kernel+3

Published

2025-08-21

·

Updated

2026-04-20

·

CVE-2025-40065

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the RISC-V KVM implementation where the hgatp register is written with valid mode bits. The RISC-V Privileged Architecture Specification requires that when MODE=Bare is selected, software must write zero to the remaining fields of hgatp. The system detects the valid mode supported by the hardware and uses a valid mode to determine the number of vmid bits supported.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-68924
BDU:2025-13787
CVE-2025-40065
ECHO-CE02-812D-1A21
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu