In the Linux kernel, the following vulnerability has been resolved:
xtensa: simdisk: add input size check in procwritesimdisk
A malicious user could pass an arbitrarily bad value to memdupusernul(), potentially causing kernel crash.
This follows the same pattern as commit ee76746387f6 ("netdevsim: prevent bad user input in nsimdevhealthbreakwrite()")
[
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"3282866768386695017540753824460473675",
"176331701726610648076329411183020549472",
"43735483369123881527932597916954547722",
"152696999916876013119261736890405054089",
"86646334368549157002597608713224544910",
"47813571977949981870580825387180742035"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d381de7fd4cdc928ede96987dc64b133e6480dd6",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c"
},
"id": "CVE-2025-40193-07d0acee"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 496.0,
"function_hash": "42137102046830192145835034800993874250"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a0c2c36d864ef3676b05cfd8c58b72ee3214cb1a",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c",
"function": "proc_write_simdisk"
},
"id": "CVE-2025-40193-0fbf2e6e"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 496.0,
"function_hash": "42137102046830192145835034800993874250"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f40405ccfb87b71175f2d5d004c0b8a0aebcc2cf",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c",
"function": "proc_write_simdisk"
},
"id": "CVE-2025-40193-3bf8d43c"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 496.0,
"function_hash": "42137102046830192145835034800993874250"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d381de7fd4cdc928ede96987dc64b133e6480dd6",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c",
"function": "proc_write_simdisk"
},
"id": "CVE-2025-40193-3c309b30"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"3282866768386695017540753824460473675",
"176331701726610648076329411183020549472",
"43735483369123881527932597916954547722",
"152696999916876013119261736890405054089",
"86646334368549157002597608713224544910",
"47813571977949981870580825387180742035"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@151bd88859474cdaccc1e4c8b21fbf72dbba2ab4",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c"
},
"id": "CVE-2025-40193-6c3ea155"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 496.0,
"function_hash": "42137102046830192145835034800993874250"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@151bd88859474cdaccc1e4c8b21fbf72dbba2ab4",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c",
"function": "proc_write_simdisk"
},
"id": "CVE-2025-40193-9027a8b7"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"3282866768386695017540753824460473675",
"176331701726610648076329411183020549472",
"43735483369123881527932597916954547722",
"152696999916876013119261736890405054089",
"86646334368549157002597608713224544910",
"47813571977949981870580825387180742035"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5d5f08fd0cd970184376bee07d59f635c8403f63",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c"
},
"id": "CVE-2025-40193-9b761d10"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 496.0,
"function_hash": "42137102046830192145835034800993874250"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5d5f08fd0cd970184376bee07d59f635c8403f63",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c",
"function": "proc_write_simdisk"
},
"id": "CVE-2025-40193-9d58c4fc"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"3282866768386695017540753824460473675",
"176331701726610648076329411183020549472",
"43735483369123881527932597916954547722",
"152696999916876013119261736890405054089",
"86646334368549157002597608713224544910",
"47813571977949981870580825387180742035"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f40405ccfb87b71175f2d5d004c0b8a0aebcc2cf",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c"
},
"id": "CVE-2025-40193-e7c05c3e"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"3282866768386695017540753824460473675",
"176331701726610648076329411183020549472",
"43735483369123881527932597916954547722",
"152696999916876013119261736890405054089",
"86646334368549157002597608713224544910",
"47813571977949981870580825387180742035"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a0c2c36d864ef3676b05cfd8c58b72ee3214cb1a",
"target": {
"file": "arch/xtensa/platforms/iss/simdisk.c"
},
"id": "CVE-2025-40193-fe384816"
}
]