目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-40113— Linux kernel 安全漏洞

AI Predicted 5.3 Difficulty: Theoretical EPSS 0.18% · P8

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 6

ベンダープロダクトVersion Rangeステータス
LinuxLinux62210f7509e13a2caa7b080722a45229b8f17a0a< ee150acd273aded01a726ce39b1f6128200799e6affected
62210f7509e13a2caa7b080722a45229b8f17a0a< 142964960c7c35de5c5f7bdd61c32699de693630affected
6.9affected
< 6.9unaffected
6.17.3≤ 6.17.*unaffected
6.18≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-40113の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
remoteproc: qcom: pas: Shutdown lite ADSP DTB on X1E
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: pas: Shutdown lite ADSP DTB on X1E The ADSP firmware on X1E has separate firmware binaries for the main firmware and the DTB. The same applies for the "lite" firmware loaded by the boot firmware. When preparing to load the new ADSP firmware we shutdown the lite_pas_id for the main firmware, but we don't shutdown the corresponding lite pas_id for the DTB. The fact that we're leaving it "running" forever becomes obvious if you try to reuse (or just access) the memory region used by the "lite" firmware: The &adsp_boot_mem is accessible, but accessing the &adsp_boot_dtb_mem results in a crash. We don't support reusing the memory regions currently, but nevertheless we should not keep part of the lite firmware running. Fix this by adding the lite_dtb_pas_id and shutting it down as well. We don't have a way to detect if the lite firmware is actually running yet, so ignore the return status of qcom_scm_pas_shutdown() for now. This was already the case before, the assignment to "ret" is not used anywhere.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未关闭lite DTB服务,可能导致内存访问冲突。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 62210f7509e13a2caa7b080722a45229b8f17a0a ~ ee150acd273aded01a726ce39b1f6128200799e6 -
LinuxLinux 6.9 -

II. CVE-2025-40113の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-40113のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-11-12 · 96 CVEs total

CVE-2025-401769.8 CRITICALtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-401408.8 HIGHnet: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
CVE-2025-401338.1 HIGHmptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
CVE-2025-401868.1 HIGHtcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
CVE-2025-401588.1 HIGHipv6: use RCU in ip6_output()
CVE-2025-402048.1 HIGHsctp: Fix MAC comparison to be constant-time
CVE-2025-401358.1 HIGHipv6: use RCU in ip6_xmit()
CVE-2025-401688.1 HIGHsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-401418.0 HIGHBluetooth: ISO: Fix possible UAF on iso_conn_free
CVE-2025-401667.8 HIGHdrm/xe/guc: Check GuC running state before deregistering exec queue
CVE-2025-401597.8 HIGHxsk: Harden userspace-supplied xdp_desc validation
CVE-2025-401737.8 HIGHnet/ip6_tunnel: Prevent perpetual tunnel growth
CVE-2025-401677.8 HIGHext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-401707.8 HIGHnet: use dst_dev_rcu() in sk_setup_caps()
CVE-2025-401727.8 HIGHaccel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
CVE-2025-401497.8 HIGHtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
CVE-2025-401747.8 HIGHx86/mm: Fix SMP ordering in switch_mm_irqs_off()
CVE-2025-401397.8 HIGHsmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
CVE-2025-401907.8 HIGHext4: guard against EA inode refcount underflow in xattr update
CVE-2025-401517.8 HIGHLoongArch: BPF: No support of struct argument in trampoline programs

Showing 20 of 96 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-40113へのコメント

まだコメントはありません


コメントを残す