CVE-2025-40239 — Linux vulnerability
15 documents6 sources
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
net: phy: micrel: always set shared->phydev for LAN8814
Currently, during the LAN8814 PTP probe shared->phydev is only set if PTP
clock gets actually set, otherwise the function will return before setting
it.
This is an issue as shared->phydev is unconditionally being used when IRQ
is being handled, especially in lan8814_gpio_process_cap and since it was
not set it will cause a NULL pointer exception and crash the kernel.
So…
Affected Packages5 packages
▶CVEListV5linux/linuxb3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 — da1ef8e9eb5d4a12bec32d11636e521e7d529b9e+3