CVE-2025-40127
Last modified
CVE-2025-40127 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwrng: ks-sa - fix division by zero in ks_sa_rng_init Fix division by zero in ks_sa_rng_init caused by missing clock pointer initialization. The clk_get_rate() call is performed on an uninitialized clk pointer, resulting in division by zero when calculating delay values. Add clock initialization code before using the clock. drivers/char/hw_random/ks-sa-rng.c | 7 +++++++ 1 file changed, 7 insertions(+). EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: hwrng: ks-sa - fix division by zero in ks_sa_rng_init Fix division by zero in ks_sa_rng_init caused by missing clock pointer initialization. The clk_get_rate() call is performed on an uninitialized clk pointer, resulting in division by zero when calculating delay values. Add clock initialization code before using the clock. drivers/char/hw_random/ks-sa-rng.c | 7 +++++++ 1 file changed, 7 insertions(+)
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < 692a04a1e0cde1d80a33df0078c755cf02cd7268; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < d76b099011fa056950f63d05ebb6160991242f6a; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < eec7e0e19c1fa75dc65e25aa6a21ef24a03849af; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < f4238064379a91e71a9c258996acac43c50c2094; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < 2b6bcce32cb5aff84588a844a4d3f6dd5353b8e2; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < 55a70e1de75e5ff5f961c79a2cdc6a4468cc2bf2; >= 6d01d8511dceb9cd40f72eb102b7d24f0b2e997b, < 612b1dfeb414dfa780a6316014ceddf9a74ff5c0 |
| Linux | Linux | 5.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40127?
How severe is CVE-2025-40127?
How do I fix CVE-2025-40127?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40121In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40122In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40123In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40124In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40125In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40126In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40128Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-40129In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-4013A vulnerability was found in PHPGurukul Art Gallery Manageme…9.8
- CVE-2025-40130In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40131In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40132In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
