cbcvebase.
CVE-2025-40255
published 2025-12-04

CVE-2025-40255: In the Linux kernel, the following vulnerability has been resolved: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() The ethtool tsconfig…

PriorityP421high7.2
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() The ethtool tsconfig Netlink path can trigger a null pointer dereference. A call chain such as: tsconfig_prepare_data() -> dev_get_hwtstamp_phylib() -> vlan_hwtstamp_get() -> generic_hwtstamp_get_lower() -> generic_hwtstamp_ioctl_lower() results in generic_hwtstamp_ioctl_lower() being called with kernel_cfg->ifr as NULL. The generic_hwtstamp_ioctl_lower() function does not expect a NULL ifr and dereferences it, leading to a system crash. Fix this by adding a NULL check for kernel_cfg->ifr in generic_hwtstamp_ioctl_lower(). If ifr is NULL, return -EINVAL.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.10-1 (forky)linux 6.17.10-1 (forky)
linuxlinux
linuxlinux>= 6e9e2eed4f39d52edf5fd006409d211facf49f6b < 8817f816ae41908e9625c0770c4af0dcdcc012388817f816ae41908e9625c0770c4af0dcdcc01238
linuxlinux>= 6e9e2eed4f39d52edf5fd006409d211facf49f6b < f796a8dec9beafcc0f6f0d3478ed685a15c5e062f796a8dec9beafcc0f6f0d3478ed685a15c5e062
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.14.0 < 6.17.106.17.10

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.