Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71422.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-71422
Upstream
Published
2025-12-04T16:16:20Z
Modified
2026-04-01T05:22:03.394102Z
Summary
CVE-2025-40266 affecting package kernel for versions less than 6.6.119.3-1
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Check the untrusted offset in FF-A memory share

Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32MAX - sizeof(struct ffacompositememregion) + 1, U32_MAX] is set from the host kernel.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.119.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71422.json"