CVE-2025-40193

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-40193
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40193.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40193
Downstream
Published
2025-11-12T21:56:31.751Z
Modified
2025-11-27T02:32:39.645413Z
Summary
xtensa: simdisk: add input size check in proc_write_simdisk
Details

In the Linux kernel, the following vulnerability has been resolved:

xtensa: simdisk: add input size check in procwritesimdisk

A malicious user could pass an arbitrarily bad value to memdupusernul(), potentially causing kernel crash.

This follows the same pattern as commit ee76746387f6 ("netdevsim: prevent bad user input in nsimdevhealthbreakwrite()")

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/40xxx/CVE-2025-40193.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6c7e873daf765e41233b9752083b66442703b7a
Fixed
f40405ccfb87b71175f2d5d004c0b8a0aebcc2cf
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6c7e873daf765e41233b9752083b66442703b7a
Fixed
151bd88859474cdaccc1e4c8b21fbf72dbba2ab4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6c7e873daf765e41233b9752083b66442703b7a
Fixed
d381de7fd4cdc928ede96987dc64b133e6480dd6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6c7e873daf765e41233b9752083b66442703b7a
Fixed
a0c2c36d864ef3676b05cfd8c58b72ee3214cb1a
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b6c7e873daf765e41233b9752083b66442703b7a
Fixed
5d5f08fd0cd970184376bee07d59f635c8403f63

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.9.0
Fixed
6.1.157
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.113
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.54
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.4