cbcvebase.
CVE-2025-40156
published 2025-11-12

CVE-2025-40156: In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: mtk-cci: Fix potential error pointer dereference in probe() The drv->sram_reg…

PriorityP419high7.8
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: mtk-cci: Fix potential error pointer dereference in probe() The drv->sram_reg pointer could be set to ERR_PTR(-EPROBE_DEFER) which would lead to a error pointer dereference. Use IS_ERR_OR_NULL() to check that the pointer is valid.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= e09bd5757b5227d6804b30c58d4587f7f87d1afa < 9cc23e221f392304b7b8aad213812564ddf6517e9cc23e221f392304b7b8aad213812564ddf6517e
linuxlinux>= e09bd5757b5227d6804b30c58d4587f7f87d1afa < 80eab6a9df7e1107dc334434dbacd0529770337780eab6a9df7e1107dc334434dbacd05297703377
linuxlinux>= e09bd5757b5227d6804b30c58d4587f7f87d1afa < 44e32104cf7e670e3d683c97b52350d8fac2332244e32104cf7e670e3d683c97b52350d8fac23322
linuxlinux>= e09bd5757b5227d6804b30c58d4587f7f87d1afa < 24d61b6e23d2c7291c528dd43a0bf76b5c05c8f024d61b6e23d2c7291c528dd43a0bf76b5c05c8f0
linuxlinux>= e09bd5757b5227d6804b30c58d4587f7f87d1afa < fc33bf0e097c6834646b98a7b3da0ae5b617f0f9fc33bf0e097c6834646b98a7b3da0ae5b617f0f9
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.1.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.