目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-40063— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.17% · P7

影响版本矩阵 6

厂商产品版本范围状态
LinuxLinux42d9f6c774790d290c175e8775ce9f1366438098< 779d3b6f2d32c5f1da6163e959abe1e1ffe2945baffected
42d9f6c774790d290c175e8775ce9f1366438098< f75f66683ded09f7135aef2e763c245a07c8271aaffected
6.16affected
< 6.16unaffected
6.17.3≤ 6.17.*unaffected
6.18≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-40063 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
crypto: comp - Use same definition of context alloc and free ops
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: comp - Use same definition of context alloc and free ops In commit 42d9f6c77479 ("crypto: acomp - Move scomp stream allocation code into acomp"), the crypto_acomp_streams struct was made to rely on having the alloc_ctx and free_ctx operations defined in the same order as the scomp_alg struct. But in that same commit, the alloc_ctx and free_ctx members of scomp_alg may be randomized by structure layout randomization, since they are contained in a pure ops structure (containing only function pointers). If the pointers within scomp_alg are randomized, but those in crypto_acomp_streams are not, then the order may no longer match. This fixes the problem by removing the union from scomp_alg so that both crypto_acomp_streams and scomp_alg will share the same definition of alloc_ctx and free_ctx, ensuring they will always have the same layout.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于alloc_ctx和free_ctx操作定义不一致,可能导致结构布局随机化问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 42d9f6c774790d290c175e8775ce9f1366438098 ~ 779d3b6f2d32c5f1da6163e959abe1e1ffe2945b -
LinuxLinux 6.16 -

二、漏洞 CVE-2025-40063 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-40063 的情报信息

登录查看更多情报信息。

CVE-2025-40063 补丁与修复 (1)

同批安全公告 · Linux · 2025-10-28 · 共 58 条

CVE-2025-40064Linux kernel 安全漏洞
CVE-2025-40075Linux kernel 安全漏洞
CVE-2025-40078Linux kernel 安全漏洞
CVE-2025-40079Linux kernel 安全漏洞
CVE-2025-40077Linux kernel 安全漏洞
CVE-2025-40081Linux kernel 安全漏洞
CVE-2025-40068Linux kernel 安全漏洞
CVE-2025-40067Linux kernel 安全漏洞
CVE-2025-40066Linux kernel 安全漏洞
CVE-2025-40065Linux kernel 安全漏洞
CVE-2025-40069Linux kernel 安全漏洞
CVE-2025-40062Linux kernel 安全漏洞
CVE-2025-40061Linux kernel 安全漏洞
CVE-2025-40060Linux kernel 安全漏洞
CVE-2025-40058Linux kernel 安全漏洞
CVE-2025-40059Linux kernel 安全漏洞
CVE-2025-40057Linux kernel 安全漏洞
CVE-2025-40056Linux kernel 安全漏洞
CVE-2025-40055Linux kernel 安全漏洞
CVE-2025-40054Linux kernel 安全漏洞

显示前 20 条,共 58 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40063

暂无评论


发表评论