VDB

DEBIAN-CVE-2025-40031

DEBIAN-CVE-2025-40031 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: tee: fix register_shm_helper() In register_shm_helper(), fix incorrect error handling for a call to iov_iter_extract_pages(). A case is missing for when iov_iter_extract_pages() only got some pages and return a number larger than 0, but not the requested amount. This fixes a possible NULL pointer dereference following a bad input from ioctl(TEE_IOC_SHM_REGISTER) where parts of the buffer isn't mapped.

Affected Products

VendorProductVersions
Debian:13linux6.12.41-1, 0, 6.12.38-1
Debian:14linux6.12.74-2, 6.12.74-2~bpo12+1, 6.13.11-1~exp1

Timeline

  • Oct 28, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›