« Volver al listado

CVE-2025-40180

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop

The cleanup loop was starting at the wrong array index, causing out-of-bounds access. Start the loop at the correct index for zero-indexed arrays to prevent accessing memory beyond the allocated array bounds.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40180",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4981b82ba2ff87df6a711fcd7a233c615df5fc79",
              "lessThan": "cd0cbf2713f6e027ebba867cb7409ae345a31312",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4981b82ba2ff87df6a711fcd7a233c615df5fc79",
              "lessThan": "ab96f08ecedd263ecaab9df8455bfb23b07fdcc2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4981b82ba2ff87df6a711fcd7a233c615df5fc79",
              "lessThan": "0aead8197fc1a85b0a89646e418feb49a564b029",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/mailbox/zynqmp-ipi-mailbox.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/mailbox/zynqmp-ipi-mailbox.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-11-12T22:15:44.737",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0aead8197fc1a85b0a89646e418feb49a564b029",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab96f08ecedd263ecaab9df8455bfb23b07fdcc2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cd0cbf2713f6e027ebba867cb7409ae345a31312",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop\n\nThe cleanup loop was starting at the wrong array index, causing\nout-of-bounds access.\nStart the loop at the correct index for zero-indexed arrays to prevent\naccessing memory beyond the allocated array bounds."
    }
  ],
  "lastModified": "2026-06-17T09:21:24.817",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}