CVE-2025-40211 — Use After Free in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.0%
top 87.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
The switch_brightness_work delayed work accesses device->brightness
and device->backlight, freed by acpi_video_dev_unregister_backlight()
during device removal.
If the work executes after acpi_video_bus_unregister_backlight()
frees these resources, it causes a use-after-free when
acpi_video_switch_brightness() dereferences device->brightness or
device->backligh…
Affected Packages7 packages
▶CVEListV5linux/linux8ab58e8e7e097bae5fe39cbc67eb93a91f7134b7 — 3f803ccf5a0c043e7c8b83f6665b082401fc8bee+8