CVE-2025-40241 | Linux Kernel up to 6.17.5 z_erofs_submit_queue compressed_bvecs[] out-of-bounds (Nessus ID 277670)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.5. Affected is the function z_erofs_submit_queue. Executing manipulation of the argument compressed_bvecs[] can lead to out-of-bounds read.
This vulnerability is registered as CVE-2025-40241. The physical device can be targeted for the attack. No exploit is available.
It is advisable to upgrade the affected component.