cbcvebase.
CVE-2025-40010
published 2025-10-20

CVE-2025-40010: In the Linux kernel, the following vulnerability has been resolved: afs: Fix potential null pointer dereference in afs_put_server afs_put_server() accessed…

PriorityP422high7.8
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved: afs: Fix potential null pointer dereference in afs_put_server afs_put_server() accessed server->debug_id before the NULL check, which could lead to a null pointer dereference. Move the debug_id assignment, ensuring we never dereference a NULL server pointer.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 2757a4dc184997c66ef1de32636f73b9f21aac14 < 7b8381f3c405b864a814d747e526e078c3ef4bc27b8381f3c405b864a814d747e526e078c3ef4bc2
linuxlinux>= 2757a4dc184997c66ef1de32636f73b9f21aac14 < cab278cead49a547ac84c3e185f446f381303eaecab278cead49a547ac84c3e185f446f381303eae
linuxlinux>= 2757a4dc184997c66ef1de32636f73b9f21aac14 < a13dbc5e20c7284b82afe6f08debdecf51d2ca04a13dbc5e20c7284b82afe6f08debdecf51d2ca04
linuxlinux>= 2757a4dc184997c66ef1de32636f73b9f21aac14 < 41782c44bb8431c43043129ae42f2ba61493847941782c44bb8431c43043129ae42f2ba614938479
linuxlinux>= 2757a4dc184997c66ef1de32636f73b9f21aac14 < 9158c6bb245113d4966df9b2ba602197a379412e9158c6bb245113d4966df9b2ba602197a379412e
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.0.0 < 6.1.1556.1.155
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.