CVE-2025-40065: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Write hgatp register with valid mode bits According to the RISC-V Privileged Architecture Spec, when MODE=Bare is selected,software must write zero to the remaining fields of hgatp. We have detected the valid mode supported by the HW before, So using a valid mode to detect how many vmid bits are supported.

Affected products

  • Linux Linux: from 5.16, before 6.17.3 (fixed in 6.17.3)

Published 2025-10-28. Last modified 2026-06-17.