CVE-2025-40255
Last modified
CVE-2025-40255 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() The ethtool tsconfig Netlink path can trigger a null pointer dereference. A call chain such as: tsconfig_prepare_data() -> dev_get_hwtstamp_phylib() -> vlan_hwtstamp_get() -> generic_hwtstamp_get_lower() -> generic_hwtstamp_ioctl_lower() results in generic_hwtstamp_ioctl_lower() being called with kernel_cfg->ifr as NULL. The generic_hwtstamp_ioctl_lower() function does not expect a NULL ifr and dereferences it, leading to a system crash. Fix this by adding a NULL check for kernel_cfg->ifr in generic_hwtstamp_ioctl_lower(). EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() The ethtool tsconfig Netlink path can trigger a null pointer dereference. A call chain such as: tsconfig_prepare_data() -> dev_get_hwtstamp_phylib() -> vlan_hwtstamp_get() -> generic_hwtstamp_get_lower() -> generic_hwtstamp_ioctl_lower() results in generic_hwtstamp_ioctl_lower() being called with kernel_cfg->ifr as NULL. The generic_hwtstamp_ioctl_lower() function does not expect a NULL ifr and dereferences it, leading to a system crash. Fix this by adding a NULL check for kernel_cfg->ifr in generic_hwtstamp_ioctl_lower(). If ifr is NULL, return -EINVAL.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6e9e2eed4f39d52edf5fd006409d211facf49f6b, < 8817f816ae41908e9625c0770c4af0dcdcc01238; >= 6e9e2eed4f39d52edf5fd006409d211facf49f6b, < f796a8dec9beafcc0f6f0d3478ed685a15c5e062 |
| Linux | Linux | 6.14 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40255?
How severe is CVE-2025-40255?
How do I fix CVE-2025-40255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4025A vulnerability classified as critical was found in itsource…9.8
- CVE-2025-40250In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40251In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-40252In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40253In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40254In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40256In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40257In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40258In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40259In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4026A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-40260In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
