PT-2025-46741 · Kvm+3 · Kvm+3

Published

2025-08-15

·

Updated

2026-02-24

·

CVE-2025-40184

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.16.0-rc7
Description The Linux kernel contains an issue within the KVM component, specifically related to debug checking for non-physical (np) guests utilizing huge mappings on the arm64 architecture. When running with transparent huge pages and CONFIG NVHE EL2 DEBUG enabled, the debug checking in assert host shared guest() can fail during the launch of an np-guest, leading to a kernel panic. The root cause is an incorrect assumption about the size of the mapping being checked. The fix involves updating the checking logic to remove the size check and assume the correct size.
Recommendations Update to a version later than 6.16.0-rc7.

Exploit

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14694
CVE-2025-40184
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Kvm
Linuxmint
Linux Kernel
Ubuntu