PT-2025-44140 · Linux+2 · Linux Kernel+2

Published

2025-09-04

·

Updated

2026-03-07

·

CVE-2025-40072

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc4
Description The do fanotify mark() function does not validate the return value of mnt ns from dentry() before dereferencing it. This can lead to a NULL pointer dereference if the path is not a mount namespace object. The issue occurs when attempting to use the fanotify mark() system call. The vulnerability was addressed by adding a check for a NULL return value from mnt ns from dentry() before dereferencing it.
Recommendations Update to a version later than 6.17.0-rc4.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16394
CVE-2025-40072
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu