PT-2025-44379 · Linux+2 · Linux Kernel+2

Published

2025-10-13

·

Updated

2026-03-07

·

CVE-2025-40089

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0dj
Description The Linux kernel contains a flaw in the cxl/features component. Specifically, the cxl feature info() function may be called with a NULL pointer when hardware does not support features, potentially leading to a kernel NULL pointer dereference. This occurs when cxl EDAC attempts to retrieve feature information and cxlfs is passed as NULL due to a lack of hardware support. A check has been added to prevent dereferencing cxlfs and return an error if no cxlfs is created.
Recommendations Update to Linux kernel version 6.17.0dj or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03985
CVE-2025-40089
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2026:10301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu