CVE-2025-40198 is a buffer over-read vulnerability in the Linux kernel's ext4 filesystem, specifically within the parse_apply_sb_mount_options() function. This flaw arises because the s_mount_opts string in the ext4 superblock is not guaranteed to be NUL-terminated, potentially leading to out-of-bounds reads. While no CVSS score is available, its FAUCET Risk Score is low at 5/100, and its EPSS score is also very low, suggesting minimal exploitability or impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 2.6.36CNA affecteddefault affected | |
| Linux | Linux | >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < 01829af7656b56d83682b3491265d583d502e502, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < 2a0cf438320cdb783e0378570744c0ef0d83e934, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < 7bf46ff83a0ef11836e38ebd72cdc5107209342d, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < 8ecb790ea8c3fc69e77bace57f14cf0d7c177bd8, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < a6e94557cd05adc82fae0400f6e17745563e5412, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < b2bac84fde28fb6a88817b8b761abda17a1d300b, >= 8b67f04ab9de5d8f3a71aef72bf02c995a506db5, < e651294218d2684302ee5ed95ccf381646f3e5b4CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026kernel: ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
Nov 12, 2025ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
Nov 11, 2025