CVE-2025-40019: Linux

EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.

Affected products

  • Linux Linux: from 5.4, before 5.4.301 (fixed in 5.4.301); from 5.5, before 5.10.246 (fixed in 5.10.246); from 5.11, before 5.15.195 (fixed in 5.15.195); from 5.16, before 6.1.157 (fixed in 6.1.157); from 6.2, before 6.6.113 (fixed in 6.6.113); from 6.7, before 6.12.54 (fixed in 6.12.54); …

Published 2025-10-24. Last modified 2026-06-17.