CVE-2025-40147 — NULL Pointer Dereference in Linux
Severity
6.2MEDIUM
No vectorEPSS
0.0%
top 94.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
blk-throttle: fix access race during throttle policy activation
On repeated cold boots we occasionally hit a NULL pointer crash in
blk_should_throtl() when throttling is consulted before the throttle
policy is fully enabled for the queue. Checking only q->td != NULL is
insufficient during early initialization, so blkg_to_pd() for the
throttle policy can still return NULL and blkg_to_tg() becomes NULL,
which later gets derefere…
Affected Packages5 packages
▶CVEListV5linux/linuxa3166c51702bb00b8f8b84022090cbab8f37be1a — 7b4bfd02c934dbbb18814ed012ecb90b58db6935+3