CVE-2025-40019
Estado: AplazadaSin puntuar—
In the Linux kernel, the following vulnerability has been resolved:
crypto: essiv - Check ssize for decryption and in-place encryption
Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/248ff2797ff52a8cbf86507f9583437443bf7685
- https://git.kernel.org/stable/c/29294dd6f1e7acf527255fb136ffde6602c3a129
- https://git.kernel.org/stable/c/6bb73db6948c2de23e407fe1b7ef94bf02b7529f
- https://git.kernel.org/stable/c/71f03f8f72d9c70ffba76980e78b38c180e61589
- https://git.kernel.org/stable/c/da7afb01ba05577ba3629f7f4824205550644986
- https://git.kernel.org/stable/c/dc4c854a5e7453c465fa73b153eba4ef2a240abe
- https://git.kernel.org/stable/c/df58651968f82344a0ed2afdafd20ecfc55ff548
- https://git.kernel.org/stable/c/f37e7860dc5e94c70b4a3e38a5809181310ea9ac
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40019",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "29294dd6f1e7acf527255fb136ffde6602c3a129",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "71f03f8f72d9c70ffba76980e78b38c180e61589",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "df58651968f82344a0ed2afdafd20ecfc55ff548",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "248ff2797ff52a8cbf86507f9583437443bf7685",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "f37e7860dc5e94c70b4a3e38a5809181310ea9ac",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "dc4c854a5e7453c465fa73b153eba4ef2a240abe",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "da7afb01ba05577ba3629f7f4824205550644986",
"versionType": "git"
},
{
"status": "affected",
"version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
"lessThan": "6bb73db6948c2de23e407fe1b7ef94bf02b7529f",
"versionType": "git"
}
],
"programFiles": [
"crypto/essiv.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.4.301",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.246",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.195",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.157",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.113",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.54",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.4",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"crypto/essiv.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-10-24T12:15:37.820",
"references": [
{
"url": "https://git.kernel.org/stable/c/248ff2797ff52a8cbf86507f9583437443bf7685",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/29294dd6f1e7acf527255fb136ffde6602c3a129",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6bb73db6948c2de23e407fe1b7ef94bf02b7529f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/71f03f8f72d9c70ffba76980e78b38c180e61589",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/da7afb01ba05577ba3629f7f4824205550644986",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dc4c854a5e7453c465fa73b153eba4ef2a240abe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/df58651968f82344a0ed2afdafd20ecfc55ff548",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f37e7860dc5e94c70b4a3e38a5809181310ea9ac",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: essiv - Check ssize for decryption and in-place encryption\n\nMove the ssize check to the start in essiv_aead_crypt so that\nit's also checked for decryption and in-place encryption."
}
],
"lastModified": "2026-06-17T09:21:07.863",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}