PT-2025-50962 · Linux+3 · Linux Kernel+3

Published

2025-11-21

·

Updated

2026-05-07

·

CVE-2025-40345

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The Linux kernel USB storage SDDR55 driver contains a flaw where out-of-bound new pba values can be accepted from a malicious device. This occurs because the driver does not properly validate the new pba value received in the status packet after each write operation. A crafted device could report values exceeding the block count derived from the device's capacity, leading to the driver accessing memory outside of allocated boundaries and potentially causing heap memory corruption. The issue stems from a lack of validation of the new pba value, which originates from the status packet following a write operation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

AZL-72332
BDU:2026-01326
CVE-2025-40345
ECHO-B05B-F115-1C9E
MGASA-2026-0017
MGASA-2026-0018
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8100-1
USN-8116-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8152-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linux Kernel
Linuxmint
Ubuntu