Junglewise Threat Intelligence

CVE-2025-40172: Linux Kernel accel/qaic general protection fault in find_and_map_user_pages

CVE-2025-40172 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Qualcomm Cloud AI (QAIC) accelerator driver. If a user or device sends a data transfer request with a size of zero, the system may attempt to access uninitialized memory. This can lead to a system crash (General Protection Fault), potentially allowing a local attacker to disrupt operations or gain unauthorized access to system resources.

Technical details

The vulnerability is a NULL pointer dereference or uninitialized memory access (General Protection Fault) within the 'accel/qaic' driver of the Linux kernel. The root cause is in the find_and_map_user_pages() function, which returns 0 without allocating a scatter-gather table (sgt) when a DMA transfer request has a length of zero or when a continuation request is received after all bytes are transferred. Subsequent calls to encode_addr_size_pairs() attempt to access this unallocated sgt. A local attacker with access to the QAIC device can trigger this by providing a zero-sized ALP. The issue has been patched by ensuring the function returns -EINVAL in these scenarios.

Affected products

  • Linux Linux Kernel 6.4.12 to 6.5, 6.6.114, 6.12.55, 6.17.5

Timeline

  • 2025-11-12: advisory: NVD published the CVE record
  • 2025-10-14: patched: Fix committed to Linux stable tree

References

Related threats