目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-40172— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.14% · P4

Affected Version Matrix 12

ベンダープロダクトVersion Rangeステータス
LinuxLinux96d3c1cadedb6ae2e8965e19cd12caa244afbd9c< 48b1d42286bfef7628b1d6c8c28d4e456c90f725affected
96d3c1cadedb6ae2e8965e19cd12caa244afbd9c< 551f1dfbcb7f3e6ed07f9d6c8c1c64337fcd0edeaffected
96d3c1cadedb6ae2e8965e19cd12caa244afbd9c< 1ab9733d14cc9987cc5dcd1f0ad1f416e302e2e6affected
96d3c1cadedb6ae2e8965e19cd12caa244afbd9c< 11f08c30a3e4157305ba692f1d44cca5fc9a8fcaaffected
d410a96e5cb8c1ec7049c83f2edcd8bbfaf5d9b3affected
6.4.12< 6.5affected
6.5affected
< 6.5unaffected
… +4 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-40172の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() Currently, if find_and_map_user_pages() takes a DMA xfer request from the user with a length field set to 0, or in a rare case, the host receives QAIC_TRANS_DMA_XFER_CONT from the device where resources->xferred_dma_size is equal to the requested transaction size, the function will return 0 before allocating an sgt or setting the fields of the dma_xfer struct. In that case, encode_addr_size_pairs() will try to access the sgt which will lead to a general protection fault. Return an EINVAL in case the user provides a zero-sized ALP, or the device requests continuation after all of the bytes have been transferred.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于find_and_map_user_pages函数未正确处理零长度请求,可能导致空指针解引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 96d3c1cadedb6ae2e8965e19cd12caa244afbd9c ~ 48b1d42286bfef7628b1d6c8c28d4e456c90f725 -
LinuxLinux 6.5 -

II. CVE-2025-40172の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-40172のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-11-12 · 96 CVEs total

CVE-2025-401769.8 CRITICALtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-401408.8 HIGHnet: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
CVE-2025-401868.1 HIGHtcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
CVE-2025-401688.1 HIGHsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-401338.1 HIGHmptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
CVE-2025-401588.1 HIGHipv6: use RCU in ip6_output()
CVE-2025-401358.1 HIGHipv6: use RCU in ip6_xmit()
CVE-2025-402048.1 HIGHsctp: Fix MAC comparison to be constant-time
CVE-2025-401418.0 HIGHBluetooth: ISO: Fix possible UAF on iso_conn_free
CVE-2025-401517.8 HIGHLoongArch: BPF: No support of struct argument in trampoline programs
CVE-2025-401597.8 HIGHxsk: Harden userspace-supplied xdp_desc validation
CVE-2025-401677.8 HIGHext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-401747.8 HIGHx86/mm: Fix SMP ordering in switch_mm_irqs_off()
CVE-2025-401667.8 HIGHdrm/xe/guc: Check GuC running state before deregistering exec queue
CVE-2025-401657.8 HIGHmedia: nxp: imx8-isi: m2m: Fix streaming cleanup on release
CVE-2025-401497.8 HIGHtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
CVE-2025-402017.8 HIGHkernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
CVE-2025-402037.8 HIGHlistmount: don't call path_put() under namespace semaphore
CVE-2025-402057.8 HIGHbtrfs: avoid potential out-of-bounds in btrfs_encode_fh()
CVE-2025-401997.8 HIGHpage_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches

Showing 20 of 96 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-40172へのコメント

まだコメントはありません


コメントを残す