
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40065 is a vulnerability discovered in the Linux kernel, specifically affecting the RISC-V KVM implementation. The vulnerability was disclosed on October 28, 2025, and involves improper handling of the hgatp register when MODE=Bare is selected (NVD, Ubuntu).
The vulnerability relates to the handling of the hgatp register in RISC-V systems. According to the RISC-V Privileged Architecture Specification, when MODE=Bare is selected, software must write zero to the remaining fields of hgatp. The issue involves the detection of valid mode supported by the hardware and using it to detect how many vmid bits are supported (NVD).
The vulnerability affects multiple Linux distributions including Ubuntu's newer releases (25.10, 25.04, 24.04 LTS) and various kernel versions. Several Ubuntu packages including linux-azure, linux-aws, and linux-gcp are marked as vulnerable in their latest versions (Ubuntu).
Some Linux distributions have already implemented fixes. For Ubuntu, older LTS releases (22.04, 20.04, 18.04, 16.04) are marked as not affected, while fixes are in progress for newer versions. Debian has fixed the issue in version 6.17.7-2 (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."