CVE-2025-40304: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
Published Dec 8, 2025
·Updated
fbdev: Add bounds checking in bitputcs to fix vmalloc-out-of-bounds
Affected Software
7 affected componentsFixes available
linux/kernel
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.112.1-2
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Dec 8, 2025
CVE Published
via MITRE·12:46 AM
Data Sourced
via MITRE·12:46 AM
Description
Data Sourced
via NVD·01:16 AM
Description
Data Sourced
via Red Hat·07:04 AM
DescriptionSeverityAffected Software
Dec 9, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:02 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40304?
CVE-2025-40304 has been assigned a high severity rating due to its potential for causing buffer overflows.
2
How do I fix CVE-2025-40304?
To fix CVE-2025-40304, update the Linux kernel to the latest version where the vulnerability has been patched.
3
What systems are affected by CVE-2025-40304?
CVE-2025-40304 affects the Linux kernel and Microsoft's azl3 kernel version 6.6.112.1-2.
4
What are the risks associated with CVE-2025-40304?
The risks associated with CVE-2025-40304 include potential system crashes and unauthorized access to system memory.
5
When was CVE-2025-40304 disclosed?
CVE-2025-40304 was disclosed recently, highlighting the need for prompt updates to vulnerable systems.