CVE-2025-40021

UnknownEPSS 0.19%

Last modified

CVE-2025-40021 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface on tracefs is compatible with kprobe_events and uprobe_events, it should also check the lockdown status and reject if it is set.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface on tracefs is compatible with kprobe_events and uprobe_events, it should also check the lockdown status and reject if it is set.

Metrics

EPSS Probability
0.19%

8.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < f3ac1f4eaba58e57943efa3e8b8d71fa7aab0abf; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < 0d41604d2d53c1abe27fefb54b37a8f6642a4d74; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < 07b1f63b5f86765793fab44d3d4c2be681cddafb; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < 3887f3814c0e770e6b73567fe0f83a2c01a6470c; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < 573b1e39edfcb7b4eecde0f1664455a1f4462eee; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < b47c4e06687a5a7b6c6ef4bd303fcfe4430b26bb; >= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5, < 456c32e3c4316654f95f9d49c12cbecfb77d5660
LinuxLinux5.4

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-40021?
In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface on tracefs is compatible with kprobe_events and uprobe_events, it should also check the lockdown status and reject if it is set.
How severe is CVE-2025-40021?
Severity scoring for CVE-2025-40021 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2025-40021?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-40021?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST