CVE-2025-40266: Linux
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.
Affected products
- Linux Linux: from 3.11, before 6.6.118 (fixed in 6.6.118); from 6.7, before 6.12.60 (fixed in 6.12.60); from 6.13, before 6.17.10 (fixed in 6.17.10)
Published 2025-12-04. Last modified 2026-07-30.