CVE-2025-40259

UnknownEPSS 0.17%

Last modified

CVE-2025-40259 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.

Metrics

EPSS Probability
0.17%

6.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 97d27b0dd015e980ade63fda111fd1353276e28b, < 11eeee00c94d770d4e45364060b5f1526dfe567b; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < db6ac8703ab2b473e1ec845f57f6dd961a388d9f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 109afbd88ecc46b6cc7551367222387e97999765; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 3dfd520c3b4ffe69e0630c580717d40447ab842f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < b343cee5df7e750d9033fba33e96fc4399fa88a5; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < b2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0f; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 6983d8375c040bb449d2187f4a57a20de01244fe; >= 97d27b0dd015e980ade63fda111fd1353276e28b, < 90449f2d1e1f020835cba5417234636937dd657e; 8d1f3b474a89b42f957ba3bae959dd3cd16531ca; fa55ef3f803fc7c20be0ab809e6278c31febd875; 6af37613289cfd32516ada47e444b48a638829c8; 4a8e8e0af9a520a685e0ab2d489327d5220d7ce2; ae9b6ae2e77947534e255903627cc62746ea77e2; >= 3.16.85, < 3.17; >= 3.18.101, < 3.19; >= 4.1.52, < 4.2; >= 4.4.123, < 4.5; >= 4.9.89, < 4.10
LinuxLinux4.12

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-40259?
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.
How severe is CVE-2025-40259?
Severity scoring for CVE-2025-40259 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2025-40259?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-40259?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST