CVE-2025-40019

Advisory lineage Upstream: 0 Downstream: 50
Deferred
Published: 24 Oct 2025, 11:44
Last modified:11 May 2026, 21:40

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
0.03% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Oct 2025, 11:44
Published
Vulnerability first disclosed
11 May 2026, 21:40
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Affected Systems

  • linuxlinux

    ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < 29294dd6f1e7acf527255fb136ffde6602c3a129 | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < 71f03f8f72d9c70ffba76980e78b38c180e61589 | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < df58651968f82344a0ed2afdafd20ecfc55ff548 | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < 248ff2797ff52a8cbf86507f9583437443bf7685 | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < f37e7860dc5e94c70b4a3e38a5809181310ea9ac | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < dc4c854a5e7453c465fa73b153eba4ef2a240abe | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < da7afb01ba05577ba3629f7f4824205550644986 | ≥ be1eb7f78aa8fbe34779c56c266ccd0364604e71, < 6bb73db6948c2de23e407fe1b7ef94bf02b7529f | 5.4

References (8)