Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40241

11
FAUCET Score

CVE-2025-40241 is a Linux kernel vulnerability affecting the erofs filesystem, specifically concerning crafted invalid encoded extents introduced in Linux 6.15. It can lead to system crashes due to out-of-bounds access or improper handling of special extent types. While no CVSS score is available, the FAUCET Risk Score is 7/100, suggesting a low severity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.15CNA affecteddefault affected
LinuxLinux
>= 1d191b4ca51d73699cb127386b95ac152af2b930, < 00d8fe0b72f4ca0a983abced36aad2160038c421, >= 1d191b4ca51d73699cb127386b95ac152af2b930, < a429b76114aaca3ef1aff4cd469dcf025431bd11CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (1)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40241

kernel: erofs: fix crafted invalid cases for encoded extents

Dec 4, 2025

References

git.kernel.org / stable/c/00d8fe0b72f4ca0a983abced36aad2160038c421
git.kernel.org / stable/c/a429b76114aaca3ef1aff4cd469dcf025431bd11