Input: imx_sc_key - fix memory corruption on unload
Summary
| CVE | CVE-2025-40262 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-04 16:16:20 UTC |
| Updated | 2026-06-02 14:16:32 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an address in the stack and so it will lead to memory corruption when the imx_sc_key_action() function is called. Remove the &. |
Risk And Classification
EPSS: 0.000580000 probability, percentile 0.183590000 (date 2026-06-08)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 3e96803b169dc948847f0fc2bae729a80914eb7b git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 4ce5218b101205b3425099fe3df88a61b58f9cc2 git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 a155292c3ce722036014da5477ee0e4c87b5e6b3 git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 ca9a08de9b294422376f47ade323d69590dbc6f2 git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 56881294915a6e866d31a46f9bcb5e19167cfbaa git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 6524a15d33951b18ac408ebbcb9c16e14e21c336 git | Not specified |
| CNA | Linux | Linux | affected 768062fd1284529212daffd360314e9aa93abb62 d83f1512758f4ef6fc5e83219fe7eeeb6b428ea4 git | Not specified |
| CNA | Linux | Linux | affected 5.8 | Not specified |
| CNA | Linux | Linux | unaffected 5.8 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.247 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.197 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.159 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.118 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.60 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.10 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
| ADP | Siemens | RUGGEDCOM RST2428P | affected V4.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/ca9a08de9b294422376f47ade323d69590dbc6f2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a155292c3ce722036014da5477ee0e4c87b5e6b3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d83f1512758f4ef6fc5e83219fe7eeeb6b428ea4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/56881294915a6e866d31a46f9bcb5e19167cfbaa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6524a15d33951b18ac408ebbcb9c16e14e21c336 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| cert-portal.siemens.com/productcert/html/ssa-253495.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/3e96803b169dc948847f0fc2bae729a80914eb7b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4ce5218b101205b3425099fe3df88a61b58f9cc2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.