PT-2025-44102 · Linux+3 · Linux Kernel+3
Published
2025-10-02
·
Updated
2026-05-19
·
CVE-2025-40034
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw within the PCI/AER subsystem. Specifically, a NULL pointer dereference can occur in the
aer ratelimit() function when processing error information supplied by platform firmware, such as through the ACPI APEI GHES mechanism. This happens when an error source device does not advertise an AER Capability, resulting in a NULL dev->aer info pointer. While pci dev aer stats incr() already includes a NULL check, aer ratelimit() did not, leading to the potential for crashes. The issue was observed with an Intel "Sky Lake-E DMI3 Registers" device that claimed to be a Root Port but lacked AER Capability advertisement. This flaw prevents ratelimiting of events from GHES.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Sky Lake-E Dmi3 Registers
Linuxmint
Linux Kernel
Ubuntu