PT-2025-44147 · Linux+3 · Linux Kernel+3

Published

2025-09-08

·

Updated

2026-05-07

·

CVE-2025-40079

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc1-g2465bb83e0b4
Description The Linux kernel contains a flaw related to how return values from BPF (Berkeley Packet Filter) programs are handled, specifically when dealing with struct operations on the RISC-V architecture. The issue arises because the BPF FIFO dequeue program returns a pointer that is treated as a 32-bit value and sign-extended to 64-bit, which is incorrect for struct operations requiring the RISC-V ABI (Application Binary Interface). This can lead to a kernel panic, as demonstrated by the ns bpf qdisc selftest triggering an inability to handle kernel paging requests.
Recommendations Update to Linux kernel version 6.17.0-rc1-g2465bb83e0b4 or a later version that includes the fix.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-16086
CVE-2025-40079
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Risc-V
Ubuntu