CVE-2025-40008

    Dashboard / Vulnerabilities / CVE-2025-40008

    CVE-2025-40008

    Published: 20 Oct 2025Last Modified: 8 Oct 2026

    Summary: kmsan: fix out-of-bounds access to shadow memory

    Details: In the Linux kernel, the following vulnerability has been resolved: kmsan: fix out-of-bounds access to shadow memory Running sha224_kunit on a KMSAN-enabled kernel results in a crash in kmsan_internal_set_shadow_origin(): BUG: unable to handle page fault for address: ffffbc3840291000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 1810067 P4D 1810067 PUD 192d067 PMD 3c17067 PTE 0 Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 81 Comm: kunit_try_catch Tainted: G N 6.17.0-rc3 #10 PREEMPT(voluntary) Tainted: [N]=TEST Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 RIP: 0010:kmsan_internal_set_shadow_origin+0x91/0x100 [...] Call Trace: <TASK> __msan_memset+0xee/0x1a0 sha224_final+0x9e/0x350 test_hash_buffer_overruns+0x46f/0x5f0 ? kmsan_get_shadow_origin_ptr+0x46/0xa0 ? __pfx_test_hash_buffer_overruns+0x10/0x10 kunit_try_run_case+0x198/0xa00 This occurs when memset() is called on a buffer that is not 4-byte aligned and extends to the end of a guard page, i.e. the next page is unmapped. The bug is that the loop at the end of kmsan_internal_set_shadow_origin() accesses the wrong shadow memory bytes when the address is not 4-byte aligned. Since each 4 bytes are associated with an origin, it rounds the address and size so that it can access all the origins that contain the buffer. However, when it checks the corresponding shadow bytes for a particular origin, it incorrectly uses the original unrounded shadow address. This results in reads from shadow memory beyond the end of the buffer's shadow memory, which crashes when that memory is not mapped. To fix this, correctly align the shadow address before accessing the 4 shadow bytes corresponding to each origin.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 9ff078f5bad8990091f1639347de5e02636e9536

    Affected versions

    v6.1.154
    v6.1.153
    v6.1.152
    v6.1.151
    v6.1.150
    v6.1.149
    v6.1.148
    v6.1.147
    v6.1.146
    v6.1.145
    v6.1.144
    v6.1.143
    v6.1.142
    v6.1.141
    v6.1.140
    v6.1.139
    v6.1.138
    v6.1.137
    v6.1.136
    v6.1.135
    v6.1.134
    v6.1.133
    v6.1.132
    v6.1.131
    v6.1.130
    v6.1.129
    v6.1.128
    v6.1.127
    v6.1.126
    v6.1.125
    v6.1.124
    v6.1.123
    v6.1.122
    v6.1.121
    v6.1.120
    v6.1.119
    v6.1.118
    v6.1.117
    v6.1.116
    v6.1.115
    v6.1.114
    v6.1.113
    v6.1.112
    v6.1.111
    v6.1.110
    v6.1.109
    v6.1.108
    v6.1.107
    v6.1.106
    v6.1.105
    v6.1.104
    v6.1.103
    v6.1.102
    v6.1.101
    v6.1.100
    v6.1.99
    v6.1.98
    v6.1.97
    v6.1.96
    v6.1.95
    v6.1.94

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2025-40008 | CVE-DB