CVE-2025-40216

Advisory lineage Upstream: 0 Downstream: 4
Deferred
Published: 04 Dec 2025, 14:14
Last modified:11 May 2026, 21:45

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
0.16% LOW
0% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Dec 2025, 14:14
Published
Vulnerability first disclosed
11 May 2026, 21:45
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, however the calculation of an offset of the first page into a folio after coalescing uses some weird bit mask logic, get rid of it.

EPSS Trends

Current EPSS score: 0.16% Percentile: 6%

Affected Systems

  • linuxlinux

    ≥ a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 50998b0ae7d9d552e96d8b7239981cf05f65eff5 | ≥ a8edbb424b1391b077407c75d8f5d2ede77aa70d, < f16769241594be59387b56ab525e327f54377e60 | ≥ a8edbb424b1391b077407c75d8f5d2ede77aa70d, < 3a3c6d61577dbb23c09df3e21f6f9eda1ecd634b | 6.12

References (3)