« Volver al listado

CVE-2025-40126

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC

The referenced commit introduced exception handlers on user-space memory references in copy_from_user and copy_to_user. These handlers return from the respective function and calculate the remaining bytes left to copy using the current register contents. This commit fixes a couple of bad calculations. This will fix the return value of copy_from_user and copy_to_user in the faulting case. The behaviour of memcpy stays unchanged.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40126",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "0bf3dc3a2156f1c5ddaba4b85d09767874634114",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "41c18baee66134e6ef786eb075c1b6adb22432b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "59424dc0d0e044b2eb007686a4724ddd91d57db5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "9b137f277cc3297044aabd950f589e505d30104c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "674ff598148a28bae0b5372339de56f2abf0b1d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "7de3a75bbc8465d816336c74d50109e73501efab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "57c278500fce3cd4e1c540700c0b05426a958393",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cb736fdbb208eb3420f1a2eb2bfc024a6e9dcada",
              "lessThan": "4fba1713001195e59cfc001ff1f2837dab877efb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1731d90d8a558ecb20cdee0c2c001ae8e15c251d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b0580eadc19ff3a617a7d07cfaf2a985153c114e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.4.34",
              "lessThan": "4.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.8.10",
              "lessThan": "4.9",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "arch/sparc/lib/U1memcpy.S"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.301",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.246",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.195",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/sparc/lib/U1memcpy.S"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-11-12T11:15:42.163",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0bf3dc3a2156f1c5ddaba4b85d09767874634114",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/41c18baee66134e6ef786eb075c1b6adb22432b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4fba1713001195e59cfc001ff1f2837dab877efb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57c278500fce3cd4e1c540700c0b05426a958393",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59424dc0d0e044b2eb007686a4724ddd91d57db5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/674ff598148a28bae0b5372339de56f2abf0b1d1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7de3a75bbc8465d816336c74d50109e73501efab",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b137f277cc3297044aabd950f589e505d30104c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC\n\nThe referenced commit introduced exception handlers on user-space memory\nreferences in copy_from_user and copy_to_user. These handlers return from\nthe respective function and calculate the remaining bytes left to copy\nusing the current register contents. This commit fixes a couple of bad\ncalculations. This will fix the return value of copy_from_user and\ncopy_to_user in the faulting case. The behaviour of memcpy stays unchanged."
    }
  ],
  "lastModified": "2026-06-17T09:21:18.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}