CVE-2025-40259
Last modified
CVE-2025-40259 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 11eeee00c94d770d4e45364060b5f1526dfe567b; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < db6ac8703ab2b473e1ec845f57f6dd961a388d9f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 109afbd88ecc46b6cc7551367222387e97999765; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 3dfd520c3b4ffe69e0630c580717d40447ab842f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < b343cee5df7e750d9033fba33e96fc4399fa88a5; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < b2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 6983d8375c040bb449d2187f4a57a20de01244fe; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 90449f2d1e1f020835cba5417234636937dd657e; 8d1f3b474a89b42f957ba3bae959dd3cd16531ca; fa55ef3f803fc7c20be0ab809e6278c31febd875; 6af37613289cfd32516ada47e444b48a638829c8; 4a8e8e0af9a520a685e0ab2d489327d5220d7ce2; ae9b6ae2e77947534e255903627cc62746ea77e2; >= 3.16.85, < 3.17; >= 3.18.101, < 3.19; >= 4.1.52, < 4.2; >= 4.4.123, < 4.5; >= 4.9.89, < 4.10 |
| Linux | Linux | 4.12 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40259?
How severe is CVE-2025-40259?
How do I fix CVE-2025-40259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40253In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40254In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40255In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40256In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40257In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40258In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-4026A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-40260In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40261In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40262In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40263In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40264In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
