PT-2025-46622 · Linux+3 · Linux Kernel+3
Published
2025-09-05
·
Updated
2026-03-13
·
CVE-2025-40147
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contained a flaw in the block I/O throttling mechanism. Specifically, a race condition existed during throttle policy activation, potentially leading to a NULL pointer dereference in
blk should throtl(). This could occur during early initialization when throttling was consulted before the throttle policy was fully enabled for the queue. The issue stemmed from insufficient checks during initialization, allowing access to throttle group state before policy data was attached. The function submit bio noacct was involved in the crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu