CVE-2025-40198: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() Unlike other strings in the ext4 superblock, we rely on tune2fs to make sure s_mount_opts is NUL terminated. Harden parse_apply_sb_mount_options() by treating s_mount_opts as a potential __nonstring.
Affected products
- Linux Linux: from 2.6.36, before 5.4.301 (fixed in 5.4.301); from 5.5, before 5.10.246 (fixed in 5.10.246); from 5.11, before 6.1.158 (fixed in 6.1.158); from 6.2, before 6.6.114 (fixed in 6.6.114); from 6.7, before 6.12.54 (fixed in 6.12.54); from 6.13, before 6.17.4 (fixed in 6.17.4)
Published 2025-11-12. Last modified 2026-07-30.