CVE-2025-40358

Source
https://cve.org/CVERecord?id=CVE-2025-40358
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40358.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40358
Downstream
Related
Published
2025-12-16T13:39:57.847Z
Modified
2026-03-09T23:50:09.483512Z
Summary
riscv: stacktrace: Disable KASAN checks for non-current tasks
Details

In the Linux kernel, the following vulnerability has been resolved:

riscv: stacktrace: Disable KASAN checks for non-current tasks

Unwinding the stack of a task other than current, KASAN would report "BUG: KASAN: out-of-bounds in walk_stackframe+0x41c/0x460"

There is a same issue on x86 and has been resolved by the commit 84936118bdf3 ("x86/unwind: Disable KASAN checks for non-current tasks") The solution could be applied to RISC-V too.

This patch also can solve the issue: https://seclists.org/oss-sec/2025/q4/23

[pjw@kernel.org: clean up checkpatch issues]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40358.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5d8544e2d0075a5f3c9a2cf27152354d54360da1
Fixed
f34ba22989da61186f30a40b6a82e0b3337b96fc
Fixed
27379fcc15a10d3e3780fe79ba3fc7ed1ccd78e2
Fixed
2c8d2b53866fb229b438296526ef0fa5a990e5e5
Fixed
060ea84a484e852b52b938f234bf9b5503a6c910

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40358.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
6.6.117
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.58
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40358.json"