CVE-2025-40034 — NULL Pointer Dereference in Linux
Severity
6.6MEDIUM
No vectorEPSS
0.0%
top 92.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
PCI/AER: Avoid NULL pointer dereference in aer_ratelimit()
When platform firmware supplies error information to the OS, e.g., via the
ACPI APEI GHES mechanism, it may identify an error source device that
doesn't advertise an AER Capability and therefore dev->aer_info, which
contains AER stats and ratelimiting data, is NULL.
pci_dev_aer_stats_incr() already checks dev->aer_info for NULL, but
aer_ratelimit() did not, leading to…
Affected Packages5 packages
▶CVEListV5linux/linuxa57f2bfb4a5863f83087867c0e671f2418212d23 — 41683624cbff0a26bb7e0627f4a7e1b51a8779a8+2