CVE-2025-40216 addresses a vulnerability in the Linux kernel's io_uring subsystem, specifically related to how user-provided virtual addresses are handled. The issue stems from an incorrect assumption about user pointer alignment, leading to flawed offset calculations within folios after coalescing. While no specific products are listed as affected, the vulnerability impacts the Linux kernel generally. The severity of this vulnerability is currently undetermined, as no CVSS score has been assigned, and the CWE is not specified. However, the FAUCET Risk Score is low at 7/100, suggesting a limited potential impact or difficulty in exploitation. The exact attack vector and complexity are not detailed in the provided information. There is no evidence of active exploitation for CVE-2025-40216. No exploit code is publicly available via Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog or on any hot lists. Community discussion and media coverage are also absent, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.12CNA affecteddefault affected | |
| Linux | Linux | >= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b, >= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 50998b0ae7d9d552e96d8b7239981cf05f65eff5, >= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < f16769241594be59387b56ab525e327f54377e60CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.