{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2025-40124",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2025-40124"
  ],
  "published": "2025-11-12T10:24:04Z",
  "summary": "sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III\n\nAnthony Yznaga tracked down that a BUG_ON in ext4 code with large folios\nenabled resulted from copy_from_user() returning impossibly large values\ngreater than the size to be copied. This lead to __copy_from_iter()\nreturning impossible values instead of the actual number of bytes it was\nable to copy.\n\nThe BUG_ON has been reported in\nhttps://lore.kernel.org/r/b14f55642207e63e907965e209f6323a0df6dcee.camel@physik.fu-berlin.de\n\nThe referenced commit introduced exception handlers on user-space memory\nreferences in copy_from_user and copy_to_user. These handlers return from\nthe respective function and calculate the remaining bytes left to copy\nusing the current register contents. The exception handlers expect that\n%o2 has already been masked during the bulk copy loop, but the masking was\nperformed after that loop. This will fix the return value of copy_from_user\nand copy_to_user in the faulting case. The behaviour of memcpy stays\nunchanged.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.1.47-1+rpt4"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-2712",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v6",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v7",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v7l",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v8",
            "binary_version": "1:6.1.47-1+rpt4"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.1.47-1+rpt4": {
            "linux_commit": "655fc658a15ae7a6f37103754adb39ba52a9a14e",
            "upstream_version": "6.1.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.156",
            "compiled_filter": false
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40124"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/fdd43fe6d286f27b826572457a89c926f97e2d3a"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/1198077606aeffb102587c6ea079ce99641c99d4"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/1857cdca12c4aff58bf26a7005a4d02850c29927"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/91eda032eb16e5d2be27c95584665bc555bb5a90"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/dc766c4830a7e1e1ee9d7f77d4ab344f2eb23c8e"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/5ef9c94d7110e90260c06868cf1dcf899b9f25ee"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/e50377c6b3f278c9f3ef017ffce17f5fcc9dace4"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/47b49c06eb62504075f0f2e2227aee2e2c2a58b3"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-08-05T12:19:11Z"
  }
}
