cbcvebase.
CVE-2025-40030
published 2025-10-28

CVE-2025-40030: In the Linux kernel, the following vulnerability has been resolved: pinctrl: check the return value of pinmux_ops::get_function_name() While the API contract…

PriorityP420high7.8
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: pinctrl: check the return value of pinmux_ops::get_function_name() While the API contract in docs doesn't specify it explicitly, the generic implementation of the get_function_name() callback from struct pinmux_ops - pinmux_generic_get_function_name() - can fail and return NULL. This is already checked in pinmux_check_ops() so add a similar check in pinmux_func_name_to_selector() instead of passing the returned pointer right down to strcmp() where the NULL can get dereferenced. This is normal operation when adding new pinfunctions.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < 1a7fc8fed2bb2e113604fde7a45432ace2056b971a7fc8fed2bb2e113604fde7a45432ace2056b97
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < e7265dc4c670b89611bcf5fe33acf99bc0aa294fe7265dc4c670b89611bcf5fe33acf99bc0aa294f
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < d77ef2f621cd1d605372c4c6ce667c496f6990c3d77ef2f621cd1d605372c4c6ce667c496f6990c3
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < ba7f7c2b2b3261e7def67018c38c69b626e0e66eba7f7c2b2b3261e7def67018c38c69b626e0e66e
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < 1a2ea887a5cd7d47bab599f733d89444df018b1a1a2ea887a5cd7d47bab599f733d89444df018b1a
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < 688c688e0bf55824f4a38f8c2180046f089a3e3b688c688e0bf55824f4a38f8c2180046f089a3e3b
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < b7e0535060a60cc99eafc19cc665d979714cd73ab7e0535060a60cc99eafc19cc665d979714cd73a
linuxlinux>= f913cfce4ee49a3382a9ff95696f49a46e56e974 < 4002ee98c022d671ecc1e4a84029e9ae7d8a56034002ee98c022d671ecc1e4a84029e9ae7d8a5603
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.19.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc6.1MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.