PT-2025-46655 · Linux+2 · Linux Kernel+2

Published

2025-10-07

·

Updated

2026-03-13

·

CVE-2025-40177

CVSS v2.0

5.5

Medium

VectorAV:L/AC:H/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s accel/qaic component related to bootlog initialization ordering. Specifically, resources required to process bootlog data from a device were being initialized after buffers were queued to receive the data, creating a race condition. This race could lead to page faults if uninitialized resources were accessed during data processing. The issue arises from incorrect initialization ordering, potentially causing problems when data is received from the device before the necessary resources are ready.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16154
CVE-2025-40177
OPENSUSE-SU-2025:20172-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20012-1
SUSE-SU-2026:20015-1
SUSE-SU-2026:20021-1
USN-7936-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu