Answer in brief
CVE-2025-40112 records a Unknown severity vulnerability in sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-40112 records a Unknown severity vulnerability in sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <05440320ea3e249d5f984918f2bf51210c1a7c03 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <7823fc4d8ab5e57f8db7806ff2530c03c166c4bb || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <37547d8e6eba87507279ee3dfddfd9dc46335454 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <a365ee556e45f780ee322b349a06efdad0c1458f || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <8cdeb5e482d3fdce7e825444b6ca3865e24c0228 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <a90ce516a73dbe087f9bf3dbf311301a58d125c6 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <088c5098ec6d6b0396edfbf3dad3e81de8469c1c || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <0b67c8fc10b13a9090340c5f8a37d308f4e1571c || bfc8be6593097cb074d3912ba2f27565cfbb7d6e || a15859f9d8396cce7c55ccdb7e75f70f14cbc349 || >=4.4.34 <4.5 || >=4.8.10 <4.9 | 05440320ea3e249d5f984918f2bf51210c1a7c03, 7823fc4d8ab5e57f8db7806ff2530c03c166c4bb, 37547d8e6eba87507279ee3dfddfd9dc46335454, a365ee556e45f780ee322b349a06efdad0c1458f, 8cdeb5e482d3fdce7e825444b6ca3865e24c0228, a90ce516a73dbe087f9bf3dbf311301a58d125c6, 088c5098ec6d6b0396edfbf3dad3e81de8469c1c, 0b67c8fc10b13a9090340c5f8a37d308f4e1571c, 4.5, 4.9 |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara The referenced commit introduced exception handlers on user-space memory references in copy_from_user and copy_to_user. These handlers return from the respective function and calculate the remaining bytes left to copy using the current register contents. This commit fixes a couple of bad calculations and a broken epilogue in the exception handlers. This will prevent crashes and ensure correct return values of copy_from_user and copy_to_user in the faulting case. The behaviour of memcpy stays unchanged.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <05440320ea3e249d5f984918f2bf51210c1a7c03 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <7823fc4d8ab5e57f8db7806ff2530c03c166c4bb || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <37547d8e6eba87507279ee3dfddfd9dc46335454 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <a365ee556e45f780ee322b349a06efdad0c1458f || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <8cdeb5e482d3fdce7e825444b6ca3865e24c0228 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <a90ce516a73dbe087f9bf3dbf311301a58d125c6 || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <088c5098ec6d6b0396edfbf3dad3e81de8469c1c || >=7ae3aaf53f1695877ccd5ebbc49ea65991e41f1e <0b67c8fc10b13a9090340c5f8a37d308f4e1571c || bfc8be6593097cb074d3912ba2f27565cfbb7d6e || a15859f9d8396cce7c55ccdb7e75f70f14cbc349 || >=4.4.34 <4.5 || >=4.8.10 <4.9 | 05440320ea3e249d5f984918f2bf51210c1a7c03, 7823fc4d8ab5e57f8db7806ff2530c03c166c4bb, 37547d8e6eba87507279ee3dfddfd9dc46335454, a365ee556e45f780ee322b349a06efdad0c1458f, 8cdeb5e482d3fdce7e825444b6ca3865e24c0228, a90ce516a73dbe087f9bf3dbf311301a58d125c6, 088c5098ec6d6b0396edfbf3dad3e81de8469c1c, 0b67c8fc10b13a9090340c5f8a37d308f4e1571c, 4.5, 4.9 |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara The referenced commit introduced exception handlers on user-space memory references in copy_from_user and copy_to_user. These handlers return from the respective function and calculate the remaining bytes left to copy using the current register contents. This commit fixes a couple of bad calculations and a broken epilogue in the exception handlers. This will prevent crashes and ensure correct return values of copy_from_user and copy_to_user in the faulting case. The behaviour of memcpy stays unchanged.
Quoted source text, attributed separately from HOL analysis.