Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40302

12
FAUCET Score

CVE-2025-40302 addresses a vulnerability in the Linux kernel's videobuf2 media framework, specifically preventing the vb2_ioctl_remove_bufs() function from being called when legacy fileio is active. This restriction is crucial to avoid potential corruption of internal buffer list pointers, which could lead to an unstable queue state during subsequent read/write operations. While no CVSS score is available, its FAUCET Risk Score of 7/100 suggests a low to moderate severity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.10CNA affecteddefault affected
LinuxLinux
>= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < 27afd6e066cfd80ddbe22a4a11b99174ac89cced, >= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < a6a493b985bfffac097a4e1be09f98b27729dca8, >= a3293a85381ec9680aa2929547fbc76c5d87a1b2, < e819b34df0a7030a15c968d619fa8a3ed2455c7aCNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (4)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40302Moderate

kernel: media: videobuf2: forbid remove_bufs when legacy fileio is active

Dec 8, 2025

References

git.kernel.org / stable/c/27afd6e066cfd80ddbe22a4a11b99174ac89cced
git.kernel.org / stable/c/a6a493b985bfffac097a4e1be09f98b27729dca8
git.kernel.org / stable/c/e819b34df0a7030a15c968d619fa8a3ed2455c7a