CVE-2025-40081
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-40081 is a vulnerability in the Linux kernel affecting the ARM SPE (Statistical Profiling Extension) performance monitoring subsystem, discovered and disclosed on October 28, 2025. The vulnerability specifically affects the PERF_IDX2OFF() function, where potential overflow could occur when handling large AUX buffer sizes greater than or equal to 2 GiB (NVD CVE, RedHat Security).

Technical details

The vulnerability exists in the Linux kernel's performance monitoring subsystem, specifically in the ARM SPE implementation. The issue arises from improper handling of nrpages casting in the PERFIDX2OFF() function, which could lead to overflow when processing AUX buffer sizes of 2 GiB or larger. The vulnerability has been assigned a CVSS v3.1 score of 7.0, indicating moderate severity with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (RedHat Security).

Impact

The vulnerability affects multiple versions of Red Hat Enterprise Linux, including versions 8, 9, and 10, as well as their real-time kernel variants (kernel-rt). The impact is considered moderate, potentially allowing local attackers with low privileges to exploit the overflow condition in the performance monitoring subsystem (RedHat Security).

Mitigation and workarounds

The vulnerability has been resolved by casting nr_pages to unsigned long to prevent overflow when handling large AUX buffer sizes. Affected systems should apply the appropriate kernel updates when available through their respective distribution channels (NVD CVE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40082N/AN/A
  • Linux KernelLinux Kernel
  • linux
NoNoOct 28, 2025
CVE-2025-40081N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoNoOct 28, 2025
CVE-2025-40080N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel-matched
NoNoOct 28, 2025
CVE-2025-40078N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel
NoNoOct 28, 2025
CVE-2025-40075N/AN/A
  • Linux KernelLinux Kernel
  • kernel-tools
NoNoOct 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management