CVE-2025-40058
Last modified
CVE-2025-40058 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Disallow dirty tracking if incoherent page walk Dirty page tracking relies on the IOMMU atomically updating the dirty bit in the paging-structure entry. For this operation to succeed, the paging- structure memory must be coherent between the IOMMU and the CPU. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Disallow dirty tracking if incoherent page walk Dirty page tracking relies on the IOMMU atomically updating the dirty bit in the paging-structure entry. For this operation to succeed, the paging- structure memory must be coherent between the IOMMU and the CPU. In another word, if the iommu page walk is incoherent, dirty page tracking doesn't work. The Intel VT-d specification, Section 3.10 "Snoop Behavior" states: "Remapping hardware encountering the need to atomically update A/EA/D bits in a paging-structure entry that is not snooped will result in a non- recoverable fault." To prevent an IOMMU from being incorrectly configured for dirty page tracking when it is operating in an incoherent mode, mark SSADS as supported only when both ecap_slads and ecap_smpwc are supported.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= f35f22cc760eb2c7034bf53251399685d611e03f, < ebe16d245a00626bb87163862a1b07daf5475a3e; >= f35f22cc760eb2c7034bf53251399685d611e03f, < 8d096ce0e87bdc361f0b25d7943543bc53aa0b9e; >= f35f22cc760eb2c7034bf53251399685d611e03f, < 57f55048e564dedd8a4546d018e29d6bbfff0a7e |
| Linux | Linux | 6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40058?
How severe is CVE-2025-40058?
How do I fix CVE-2025-40058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40052In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40053In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-40054In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40055In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40056In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40057In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40059In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4006A vulnerability classified as critical has been found in you…5.1
- CVE-2025-40060In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40061In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40062In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40063In the Linux kernel, the following vulnerability has been re…7
Are you affected by CVE-2025-40058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
