CVE-2025-40198

Source
https://cve.org/CVERecord?id=CVE-2025-40198
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40198.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40198
Downstream
Related
Published
2025-11-12T21:56:33.220Z
Modified
2026-03-12T03:54:35.777824Z
Summary
ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
Details

In the Linux kernel, the following vulnerability has been resolved:

ext4: avoid potential buffer over-read in parseapplysbmountoptions()

Unlike other strings in the ext4 superblock, we rely on tune2fs to make sure smountopts is NUL terminated. Harden parseapplysbmountoptions() by treating smountopts as a potential __nonstring.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40198.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b67f04ab9de5d8f3a71aef72bf02c995a506db5
Fixed
7bf46ff83a0ef11836e38ebd72cdc5107209342d
Fixed
b2bac84fde28fb6a88817b8b761abda17a1d300b
Fixed
e651294218d2684302ee5ed95ccf381646f3e5b4
Fixed
01829af7656b56d83682b3491265d583d502e502
Fixed
2a0cf438320cdb783e0378570744c0ef0d83e934
Fixed
a6e94557cd05adc82fae0400f6e17745563e5412
Fixed
8ecb790ea8c3fc69e77bace57f14cf0d7c177bd8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40198.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.36
Fixed
5.4.301
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.246
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
6.1.158
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.114
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.54
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40198.json"