目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-40319— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 16

ベンダープロダクトVersion Rangeステータス
LinuxLinux457f44363a8894135c85b7a9afd2bd8196db24ab< 47626748a2a00068dbbd5836d19076637b4e235baffected
457f44363a8894135c85b7a9afd2bd8196db24ab< de2ce6b14bc3e565708a39bdba3ef9162aeffc72affected
457f44363a8894135c85b7a9afd2bd8196db24ab< e1828c7a8d8135e21ff6adaaa9458c32aae13b11affected
457f44363a8894135c85b7a9afd2bd8196db24ab< 6451141103547f4efd774e912418a3b4318046c6affected
457f44363a8894135c85b7a9afd2bd8196db24ab< 10ca3b2eec384628bc9f5d8190aed9427ad2dde6affected
457f44363a8894135c85b7a9afd2bd8196db24ab< 430e15544f11f8de26b2b5109c7152f71b78295eaffected
457f44363a8894135c85b7a9afd2bd8196db24ab< 4e9077638301816a7d73fa1e1b4c1db4a7e3b59caffected
5.8affected
… +8 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-40319の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
bpf: Sync pending IRQ work before freeing ring buffer
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work can be queued in bpf_ringbuf_commit() but the ring buffer is freed before the work executes. In the syzbot reproducer, a BPF program attached to sched_switch triggers bpf_ringbuf_commit(), queuing an irq_work. If the ring buffer is freed before this work executes, the irq_work thread may accesses freed memory. Calling `irq_work_sync(&rb->work)` ensures that all pending irq_work complete before freeing the buffer.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未同步挂起的IRQ工作,可能导致内存损坏。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 457f44363a8894135c85b7a9afd2bd8196db24ab ~ 47626748a2a00068dbbd5836d19076637b4e235b -
LinuxLinux 5.8 -

II. CVE-2025-40319の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-40319のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-08 · 82 CVEs total

CVE-2023-537519.8 CRITICALcifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
CVE-2025-403209.8 CRITICALsmb: client: fix potential cfid UAF in smb2_query_info_compound
CVE-2023-537699.3 CRITICALvirt/coco/sev-guest: Double-buffer messages
CVE-2025-403188.8 HIGHBluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
CVE-2023-537648.8 HIGHwifi: ath12k: Handle lock during peer_id find
CVE-2023-537628.8 HIGHBluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
CVE-2025-402928.4 HIGHvirtio-net: fix received length check in big packets
CVE-2025-403098.0 HIGHBluetooth: SCO: Fix UAF on sco_conn_free
CVE-2025-403027.8 HIGHmedia: videobuf2: forbid remove_bufs when legacy fileio is active
CVE-2023-537637.8 HIGHRevert "f2fs: fix to do sanity check on extent cache correctly"
CVE-2023-537687.8 HIGHregmap-irq: Fix out-of-bounds access when allocating config buffers
CVE-2025-402977.8 HIGHnet: bridge: fix use-after-free due to MST port state bypass
CVE-2022-506307.8 HIGHmm: hugetlb: fix UAF in hugetlb_handle_userfault
CVE-2022-506237.8 HIGHfpga: prevent integer overflow in dfl_feature_ioctl_set_irq()
CVE-2023-537597.8 HIGHHID: hidraw: fix data race on device refcount
CVE-2025-403177.8 HIGHregmap: slimbus: fix bus_context pointer in regmap init calls
CVE-2023-537477.8 HIGHvc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF
CVE-2025-403237.8 HIGHfbcon: Set fb_display[i]->mode to NULL when the mode is released
CVE-2023-537537.8 HIGHdrm/amd/display: fix mapping to non-allocated address
CVE-2023-537527.8 HIGHnet: deal with integer overflows in kmalloc_reserve()

Showing 20 of 82 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-40319へのコメント

まだコメントはありません


コメントを残す