cbcvebase.
CVE-2025-40299
published 2025-12-08

CVE-2025-40299: In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole use of…

PriorityP420
EPSS
0.18%
7.8th percentile
In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole use of do_aux_work at this time. ptp_clock_gettime() and ptp_sys_offset() assume every ptp_clock has implemented either gettimex64 or gettime64. Stub gettimex64 and return -EOPNOTSUPP to prevent NULL dereferencing.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= acd16380523b400400523fe54c7499320e558e80 < 96ec90412ceb58c73fd3714e40ab2cee1eedac3b96ec90412ceb58c73fd3714e40ab2cee1eedac3b
linuxlinux>= acd16380523b400400523fe54c7499320e558e80 < 6ab753b5d8e521616cd9bd10b09891cbeb7e02356ab753b5d8e521616cd9bd10b09891cbeb7e0235
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.17.0 < 6.17.86.17.8
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.