VDB
DEBIAN-CVE-2025-40031
DEBIAN-CVE-2025-40031
PUBLISHED
In the Linux kernel, the following vulnerability has been resolved: tee: fix register_shm_helper() In register_shm_helper(), fix incorrect error handling for a call to iov_iter_extract_pages(). A case is missing for when iov_iter_extract_pages() only got some pages and return a number larger than 0, but not the requested amount. This fixes a possible NULL pointer dereference following a bad input from ioctl(TEE_IOC_SHM_REGISTER) where parts of the buffer isn't mapped.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | linux | 6.12.41-1, 0, 6.12.38-1 |
| Debian:14 | linux | 6.12.74-2, 6.12.74-2~bpo12+1, 6.13.11-1~exp1 |
Timeline
- Oct 28, 2025 CVE Published
- Apr 28, 2026 CVE Updated