CVE-2025-40102 describes a vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) for arm64 architectures. It allows userspace to pend vCPU events before the vCPU is properly initialized, leading to the KVM interpreting uninitialized data. This can result in a kernel bug and system crash, as demonstrated by a specific case where the vCPU enters an illegal mode. The severity is moderate, with a FAUCET Risk Score of 5/100. The attack vector involves specific KVM ioctls, and the complexity appears to be low given the direct manipulation of vCPU events. The potential impact is a denial of service due to a kernel crash. There is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 4.19CNA affecteddefault affected | |
| Linux | Linux | >= b7b27facc7b50a5fce0afaa3df56157136ce181a, < 0aa1b76fe1429629215a7c79820e4b96233ac4a3, >= b7b27facc7b50a5fce0afaa3df56157136ce181a, < 64a04e6320fc5affbadc59dc7024d79f909bfe84CNA affecteddefault unaffected |
CVSS version used by this source: FAUCET enrichment
No media coverage found for this CVE.