cbcvebase.
CVE-2025-40125
published 2025-11-12

CVE-2025-40125: In the Linux kernel, the following vulnerability has been resolved: blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx In…

PriorityP420high7.8
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx In __blk_mq_update_nr_hw_queues() the return value of blk_mq_sysfs_register_hctxs() is not checked. If sysfs creation for hctx fails, later changing the number of hw_queues or removing disk will trigger the following warning: kernfs: can not remove 'nr_tags', no directory WARNING: CPU: 2 PID: 637 at fs/kernfs/dir.c:1707 kernfs_remove_by_name_ns+0x13f/0x160 Call Trace: remove_files.isra.1+0x38/0xb0 sysfs_remove_group+0x4d/0x100 sysfs_remove_groups+0x31/0x60 __kobject_del+0x23/0xf0 kobject_del+0x17/0x40 blk_mq_unregister_hctx+0x5d/0x80 blk_mq_sysfs_unregister_hctxs+0x94/0xd0 blk_mq_update_nr_hw_queues+0x124/0x760 nullb_update_nr_hw_queues+0x71/0xf0 [null_blk] nullb_device_submit_queues_store+0x92/0x120 [null_blk] kobjct_del() was called unconditionally even if sysfs creation failed. Fix it by checkig the kobject creation statusbefore deleting it.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < a8c53553f1833cc2d14175d2d72cf37193a01898a8c53553f1833cc2d14175d2d72cf37193a01898
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < cc14ea21c4e658814d737ed4dedde6cd626a15adcc14ea21c4e658814d737ed4dedde6cd626a15ad
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < 4b97e99b87a773d52699521d40864f3ec888e9a64b97e99b87a773d52699521d40864f3ec888e9a6
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < 6e7dadc5763c48eb3b9b91265a21f312599ebb2c6e7dadc5763c48eb3b9b91265a21f312599ebb2c
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < 06c4826b1d900611096e4621e93133db57e1391106c4826b1d900611096e4621e93133db57e13911
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < babc634e9fe2803962dba98a07587e835dbc0731babc634e9fe2803962dba98a07587e835dbc0731
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < d5ddd76ee52bdc16e9f8b1e7791291e785dab032d5ddd76ee52bdc16e9f8b1e7791291e785dab032
linuxlinux>= 477e19dedc9d3e1f4443a1d4ae00572a988120ea < 4c7ef92f6d4d08a27d676e4c348f4e2922cab3ed4c7ef92f6d4d08a27d676e4c348f4e2922cab3ed
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.20.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.