CVE-2025-40130 — Missing Synchronization in Linux
Severity
6.8MEDIUM
No vectorEPSS
0.0%
top 94.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: ufs: core: Fix data race in CPU latency PM QoS request handling
The cpu_latency_qos_add/remove/update_request interfaces lack internal
synchronization by design, requiring the caller to ensure thread safety.
The current implementation relies on the 'pm_qos_enabled' flag, which is
insufficient to prevent concurrent access and cannot serve as a proper
synchronization mechanism. This has led to data races and list
corruptio…
Affected Packages5 packages
▶CVEListV5linux/linux2777e73fc154e2e87233bdcc0e2402b33815198e — d9df61afb8d23c475f1be3c714da2c34c156ab01+2