PT-2025-49429 · Lenovo+4 · Thinkpad X9+4

Published

2025-12-08

·

Updated

2026-02-24

·

CVE-2025-40296

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to a double free of a GPIO device during unregistration. Specifically, the regulator unregister() function already frees the associated GPIO device, and a redundant release during unregistration causes this issue. This can lead to random failures, particularly when other drivers attempt to allocate interrupts, as observed on ThinkPad X9 (Lunar Lake) systems. The root cause is an unexpected drop in the reference count of the pinctrl intel platform module when the driver defers its probe. The issue can also be reproduced by directly unloading the module. The vulnerable function is regulator unregister().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-40296
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linuxmint
Linux Kernel
Thinkpad X9
Ubuntu
Pinctrl Intel Platform