{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-40259","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.182Z","datePublished":"2025-12-04T16:08:19.904Z","dateUpdated":"2026-05-11T21:45:52.770Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T21:45:52.770Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sg: Do not sleep in atomic context\n\nsg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may\nsleep. Hence, call sg_finish_rem_req() with interrupts enabled instead\nof disabled."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/sg.c"],"versions":[{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"11eeee00c94d770d4e45364060b5f1526dfe567b","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"db6ac8703ab2b473e1ec845f57f6dd961a388d9f","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"109afbd88ecc46b6cc7551367222387e97999765","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"3dfd520c3b4ffe69e0630c580717d40447ab842f","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"b343cee5df7e750d9033fba33e96fc4399fa88a5","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"b2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0f","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"6983d8375c040bb449d2187f4a57a20de01244fe","status":"affected","versionType":"git"},{"version":"97d27b0dd015e980ade63fda111fd1353276e28b","lessThan":"90449f2d1e1f020835cba5417234636937dd657e","status":"affected","versionType":"git"},{"version":"8d1f3b474a89b42f957ba3bae959dd3cd16531ca","status":"affected","versionType":"git"},{"version":"fa55ef3f803fc7c20be0ab809e6278c31febd875","status":"affected","versionType":"git"},{"version":"6af37613289cfd32516ada47e444b48a638829c8","status":"affected","versionType":"git"},{"version":"4a8e8e0af9a520a685e0ab2d489327d5220d7ce2","status":"affected","versionType":"git"},{"version":"ae9b6ae2e77947534e255903627cc62746ea77e2","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/sg.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.4.302","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.247","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.197","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.159","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.118","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.60","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.17.10","lessThanOrEqual":"6.17.*","status":"unaffected","versionType":"semver"},{"version":"6.18","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.4.302"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.10.247"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.197"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.159"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.118"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.60"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.17.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16.85"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.123"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.89"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/11eeee00c94d770d4e45364060b5f1526dfe567b"},{"url":"https://git.kernel.org/stable/c/db6ac8703ab2b473e1ec845f57f6dd961a388d9f"},{"url":"https://git.kernel.org/stable/c/109afbd88ecc46b6cc7551367222387e97999765"},{"url":"https://git.kernel.org/stable/c/3dfd520c3b4ffe69e0630c580717d40447ab842f"},{"url":"https://git.kernel.org/stable/c/b343cee5df7e750d9033fba33e96fc4399fa88a5"},{"url":"https://git.kernel.org/stable/c/b2c0340cfa25c5c1f65e8590cc1a2dc97d14ef0f"},{"url":"https://git.kernel.org/stable/c/6983d8375c040bb449d2187f4a57a20de01244fe"},{"url":"https://git.kernel.org/stable/c/90449f2d1e1f020835cba5417234636937dd657e"}],"title":"scsi: sg: Do not sleep in atomic context","x_generator":{"engine":"bippy-1.2.0"}}}}