A recently assigned CVE identifier, CVE-2025-40293, closes a subtle arithmetic bug in the Linux kernel’s iommufd dirty-tracking code that could produce a divide-by-zero kernel fault when unusual page-size shift values are used; upstream maintainers reorganized the arithmetic to avoid overflow...