Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40216

11
FAUCET Score

CVE-2025-40216 addresses a vulnerability in the Linux kernel's io_uring subsystem, specifically related to how user-provided virtual addresses are handled. The issue stems from an incorrect assumption about user pointer alignment, leading to flawed offset calculations within folios after coalescing. While no specific products are listed as affected, the vulnerability impacts the Linux kernel generally. The severity of this vulnerability is currently undetermined, as no CVSS score has been assigned, and the CWE is not specified. However, the FAUCET Risk Score is low at 7/100, suggesting a limited potential impact or difficulty in exploitation. The exact attack vector and complexity are not detailed in the provided information. There is no evidence of active exploitation for CVE-2025-40216. No exploit code is publicly available via Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog or on any hot lists. Community discussion and media coverage are also absent, indicating a lack of widespread attention.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.12CNA affecteddefault affected
LinuxLinux
>= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b, >= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 50998b0ae7d9d552e96d8b7239981cf05f65eff5, >= a8edbb424b1391b077407c75d8f5d2ede77aa70d, < f16769241594be59387b56ab525e327f54377e60CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Patches (3)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2025-40216Moderate

kernel: io_uring/rsrc: don't rely on user vaddr alignment

Dec 4, 2025

References

git.kernel.org / stable/c/3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b
git.kernel.org / stable/c/50998b0ae7d9d552e96d8b7239981cf05f65eff5
git.kernel.org / stable/c/f16769241594be59387b56ab525e327f54377e60