CVE-2025-40059
BaseFortify
Publication date: 2025-10-28
Last updated on: 2025-10-30
Assigner: kernel.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the Linux kernel involves incorrect handling of the return value from the function devm_kzalloc in the coresight component. Specifically, devm_kzalloc could return a null pointer, and the code did not properly check for this condition. The fix involves using "!desc.pdata" to correctly handle the null return value, preventing potential issues caused by dereferencing a null pointer.
How can this vulnerability impact me? :
If the return value of devm_kzalloc is not properly checked and is null, it could lead to null pointer dereferences in the Linux kernel, potentially causing system crashes or instability. This could impact system reliability and availability.