{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-40117","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.168Z","datePublished":"2025-11-12T10:23:17.851Z","dateUpdated":"2026-08-05T12:07:53.958Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:07:53.958Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: pci_endpoint_test: Fix array underflow in pci_endpoint_test_ioctl()\n\nCommit eefb83790a0d (\"misc: pci_endpoint_test: Add doorbell test case\")\nadded NO_BAR (-1) to the pci_barno enum which, in practical terms,\nchanges the enum from an unsigned int to a signed int.  If the user\npasses a negative number in pci_endpoint_test_ioctl() then it results in\nan array underflow in pci_endpoint_test_bar()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is triggered by a PCITEST_BAR ioctl on the local misc device /dev/pci-endpoint-test.N, requiring local system access rather than any network or physical interaction.\nAC:L - A single ioctl with any negative argument deterministically defeats the signed `bar > BAR_5` check; there is no race, no timing window, and no dependence on state outside the attacker's control.\nPR:L - The driver performs no capability check at all — no CAP_SYS_ADMIN, no .open hook, nothing — so any local user holding a descriptor to the test device node can trigger it, and on the PCI-endpoint test rigs where this driver is deployed the node is commonly exposed to the non-root test-automation account.\nUI:N - The attacker performs the entire attack via its own ioctl call; no victim action or cooperation is needed.\nS:U - The out-of-bounds accesses corrupt kernel memory and MMIO mappings within the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The attacker-controlled negative index produces out-of-bounds reads of `pdev->resource[]`, of `struct pci_endpoint_test`, of `.rodata`, and a `memcpy_fromio()` of up to 1 MB from an OOB-derived pointer, and the resulting memory-corruption primitive can be leveraged for arbitrary kernel memory disclosure.\nI:H - `memcpy_toio(test->bar[barno] + offset, ...)` writes megabytes of pattern data to a destination pointer read from out-of-bounds memory at an attacker-chosen index, clobbering kernel heap objects (including `struct pci_dev`) or adjacent device MMIO registers — an arbitrary-write primitive exploitable for control-flow hijacking.\nA:H - The loop bound comes from a garbage `bar_size` read out of bounds, so the write runs far past any valid mapping and reliably faults, and the heap corruption itself guarantees a kernel oops or panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/pci_endpoint_test.c"],"versions":[{"version":"eefb83790a0dda112d1755e4f5e213738d717e76","lessThan":"6df3687922570f753574c40b35e83b26b32292d0","status":"affected","versionType":"git"},{"version":"eefb83790a0dda112d1755e4f5e213738d717e76","lessThan":"1ad82f9db13d85667366044acdfb02009d576c5a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/pci_endpoint_test.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.17.3","lessThanOrEqual":"6.17.*","status":"unaffected","versionType":"semver"},{"version":"6.18","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.17.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6df3687922570f753574c40b35e83b26b32292d0"},{"url":"https://git.kernel.org/stable/c/1ad82f9db13d85667366044acdfb02009d576c5a"}],"title":"misc: pci_endpoint_test: Fix array underflow in pci_endpoint_test_ioctl()","x_generator":{"engine":"bippy-1.2.0"}}}}