Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40091

12
FAUCET Score

CVE-2025-40091 describes a use-after-free (UAF) vulnerability in the Linux kernel's ixgbe network driver. This flaw occurs because the devlink_free() function is called prematurely during the ixgbe_remove() process, leading to memory being freed while still in use. The vulnerability specifically impacts systems utilizing the ixgbe driver. The severity of this UAF is moderate, with a FAUCET Risk Score of 5/100. While a direct attack vector isn't explicitly detailed, UAF vulnerabilities can often lead to denial-of-service, information disclosure, or potentially arbitrary code execution, depending on the specific memory layout and attacker control. The complexity of exploitation is likely high, requiring specific conditions during driver removal. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Its EPSS score is very low, indicating a minimal likelihood of exploitation in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.16CNA affecteddefault affected
LinuxLinux
>= a0285236ab93fdfdd1008afaa04561d142d6c276, < 5feef67b646d8f5064bac288e22204ffba2b9a4a, >= a0285236ab93fdfdd1008afaa04561d142d6c276, < df445969aa727cd64f3f29dc1f85fb60aca238d1CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
7.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (4)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40091Moderate

kernel: ixgbe: fix too early devlink_free() in ixgbe_remove()

Oct 30, 2025

References

git.kernel.org / stable/c/5feef67b646d8f5064bac288e22204ffba2b9a4a
git.kernel.org / stable/c/df445969aa727cd64f3f29dc1f85fb60aca238d1