CVE-2025-40302 addresses a vulnerability in the Linux kernel's videobuf2 media framework, specifically preventing the vb2_ioctl_remove_bufs() function from being called when legacy fileio is active. This restriction is crucial to avoid potential corruption of internal buffer list pointers, which could lead to an unstable queue state during subsequent read/write operations. While no CVSS score is available, its FAUCET Risk Score of 7/100 suggests a low to moderate severity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.10CNA affecteddefault affected | |
| Linux | Linux | >= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < 27afd6e066cfd80ddbe22a4a11b99174ac89cced, >= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < a6a493b985bfffac097a4e1be09f98b27729dca8, >= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < e819b34df0a7030a15c968d619fa8a3ed2455c7aCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.