cbcvebase.
CVE-2025-40021
published 2025-10-24

CVE-2025-40021: In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface…

PriorityP421high7.8
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface on tracefs is compatible with kprobe_events and uprobe_events, it should also check the lockdown status and reject if it is set.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < f3ac1f4eaba58e57943efa3e8b8d71fa7aab0abff3ac1f4eaba58e57943efa3e8b8d71fa7aab0abf
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < 0d41604d2d53c1abe27fefb54b37a8f6642a4d740d41604d2d53c1abe27fefb54b37a8f6642a4d74
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < 07b1f63b5f86765793fab44d3d4c2be681cddafb07b1f63b5f86765793fab44d3d4c2be681cddafb
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < 3887f3814c0e770e6b73567fe0f83a2c01a6470c3887f3814c0e770e6b73567fe0f83a2c01a6470c
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < 573b1e39edfcb7b4eecde0f1664455a1f4462eee573b1e39edfcb7b4eecde0f1664455a1f4462eee
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < b47c4e06687a5a7b6c6ef4bd303fcfe4430b26bbb47c4e06687a5a7b6c6ef4bd303fcfe4430b26bb
linuxlinux>= 17911ff38aa58d3c95c07589dbf5d3564c4cf3c5 < 456c32e3c4316654f95f9d49c12cbecfb77d5660456c32e3c4316654f95f9d49c12cbecfb77d5660
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.11.0 < 5.15.1945.15.194
linuxlinux_kernel>= 5.16.0 < 6.1.1556.1.155
linuxlinux_kernel>= 5.4.0 < 5.10.2455.10.245
linuxlinux_kernel>= 6.13.0 < 6.16.106.16.10
linuxlinux_kernel>= 6.2.0 < 6.6.1096.6.109
linuxlinux_kernel>= 6.7.0 < 6.12.506.12.50
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
ubuntulinux-azure-5.15
ubuntulinux-intel-iotg-5.15

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat4.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.