CVE-2025-40019

Linux Kernel - Crypto Vuln

Title source: llm

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.

Exploits (3)

nomisec WORKING POC 1 stars
by guard-wait · poc
https://github.com/guard-wait/CVE-2025-40019_POC
nomisec WORKING POC
by 0xAtharv · poc
https://github.com/0xAtharv/CVE-2025-40019-POC
nomisec WORKING POC
by xooxo · poc
https://github.com/xooxo/CVE-2025-40019-Essiv

Scores

EPSS 0.0002
EPSS Percentile 4.9%

Classification

Status draft

Affected Products (7)

linux/Kernel < 5.4.301linux
linux/Kernel < 5.10.246linux
linux/Kernel < 5.15.195linux
linux/Kernel < 6.1.157linux
linux/Kernel < 6.6.113linux
linux/Kernel < 6.12.54linux
linux/Kernel < 6.17.4linux

Timeline

Published Oct 24, 2025
Tracked Since Feb 18, 2026