PT-2025-46622 · Linux+3 · Linux Kernel+3

Published

2025-09-05

·

Updated

2026-03-13

·

CVE-2025-40147

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contained a flaw in the block I/O throttling mechanism. Specifically, a race condition existed during throttle policy activation, potentially leading to a NULL pointer dereference in blk should throtl(). This could occur during early initialization when throttling was consulted before the throttle policy was fully enabled for the queue. The issue stemmed from insufficient checks during initialization, allowing access to throttle group state before policy data was attached. The function submit bio noacct was involved in the crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16143
CVE-2025-40147
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu