PT-2025-46595 · Linux+3 · Linux Kernel+3

Published

2025-10-05

·

Updated

2026-05-07

·

CVE-2025-40120

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to USB runtime power management (PM) and Real-Time Network Layer (RTNL) interactions with the AX88772* network adapter. The issue arises when runtime PM is enabled, potentially leading to deadlocks or problems with power management and Medium Dependent Interface (MDIO) operations. Specifically, the ndo open() function, operating under RTNL, might trigger a resume operation (usb autopm get interface()) while holding the USB PM lock. This resume path then invokes phylink/phylib and MDIO, which also require RTNL, creating a potential deadlock scenario. To address this, a usage reference is held to keep the device runtime-PM active during binding and released during unbinding, preventing runtime suspend regardless of system settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2025-15303
CVE-2025-40120
DLA-4379-1
OESA-2025-2765
OESA-2025-2766
OESA-2025-2767
OPENSUSE-SU-2025:20172-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4422-1
SUSE-SU-2025:4505-1
SUSE-SU-2025:4516-1
SUSE-SU-2025:4517-1
SUSE-SU-2025:4521-1
SUSE-SU-2026:20012-1
SUSE-SU-2026:20015-1
SUSE-SU-2026:20021-1
SUSE-SU-2026:20039-1
SUSE-SU-2026:20059-1
SUSE-SU-2026:20473-1
SUSE-SU-2026:20496-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Ax88772
Linuxmint
Linux Kernel
Ubuntu