CVE-2025-40216: Linux

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, however the calculation of an offset of the first page into a folio after coalescing uses some weird bit mask logic, get rid of it.

Affected products

  • Linux Linux: from 6.12, before 6.12.36 (fixed in 6.12.36); from 6.13, before 6.15.5 (fixed in 6.15.5)

Published 2025-12-04. Last modified 2026-07-30.