Review reviewHigh

CVE-2025-40027

Linux

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as below: general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f] CPU: 0 PID: 5083 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00037-g855bd1d7d838 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:__list_del include/linux/list.h:114 [inline] RIP: 0010:__list_de...

CVSS
7.8
EPSS
0.15%
4.73% percentile
CISA KEV
Not listed
Published
2025.10.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as below: general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f] CPU: 0 PID: 5083 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00037-g855bd1d7d838 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:__list_del include/linux/list.h:114 [inline] RIP: 0010:__list_de...

Affected product and versions

Product
Linux
Affected versions
>= afd8d65411551839b7ab14a539d00075b2793451 < a5901a0dfb5964525990106706ae8b98db098226, >= afd8d65411551839b7ab14a539d00075b2793451 < 5c64c0b7b3446f7ed088a13bc8d7487d66534cbb, >= afd8d65411551839b7ab14a539d00075b2793451 < c1db864270eb7fea94a9ef201da0c9dc1cbab7b8, >= afd8d65411551839b7ab14a539d00075b2793451 < 0e0097005abc02c9f262370674f855625f4f3fb4, >= afd8d65411551839b7ab14a539d00075b2793451 < 284e67a93b8c48952b6fc82129a8d3eb9dc73b06, >= afd8d65411551839b7ab14a539d00075b2793451 < 716dceb19a9f8ff6c9d3aee5a771a93d6a47a0b6, >= afd8d65411551839b7ab14a539d00075b2793451 < 448db01a48e1cdbbc31c995716a5dac1e52ba036, >= afd8d65411551839b7ab14a539d00075b2793451 < 94797b84cb9985022eb9cb3275c9497fbc883bb6, >= afd8d65411551839b7ab14a539d00075b2793451 < 674b56aa57f9379854cb6798c3bbcef7e7b51ab7, >= 3.15
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available