PT-2025-49049 · Linux+2 · Linux Kernel+2

CVE-2025-40222

·

Published

2025-09-23

·

Updated

2026-05-26

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc1+ #30
Description The Linux kernel contains a flaw in the serial handling code for the SH-SCI (SuperH Serial Communication Interface). Specifically, the receive error handling code incorrectly manages FIFO overrun conditions for RSCI (Receive Status Control Interrupt) ports. The issue arises from an incorrect memory offset used when accessing the overrun register for RSCI, leading to out-of-bounds access and a potential system crash. The sci serial in() function and sci handle fifo overrun() are involved in this issue. The sci getreg() function is called with an invalid register index, causing the system to access memory outside the expected bounds of the RSCI port parameters structure. This results in a warning message indicating an invalid register access. The problem does not affect the sci mpxed interrupt() interrupt handler, as it is not used for RSCI.
Recommendations Update to a version newer than 6.17.0-rc1+ #30.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10380
CVE-2025-40222
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu