CVE-2025-40091 describes a use-after-free (UAF) vulnerability in the Linux kernel's ixgbe network driver. This flaw occurs because the devlink_free() function is called prematurely during the ixgbe_remove() process, leading to memory being freed while still in use. The vulnerability specifically impacts systems utilizing the ixgbe driver. The severity of this UAF is moderate, with a FAUCET Risk Score of 5/100. While a direct attack vector isn't explicitly detailed, UAF vulnerabilities can often lead to denial-of-service, information disclosure, or potentially arbitrary code execution, depending on the specific memory layout and attacker control. The complexity of exploitation is likely high, requiring specific conditions during driver removal. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Its EPSS score is very low, indicating a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.16CNA affecteddefault affected | |
| Linux | Linux | >= a0285236ab93fdfdd1008afaa04561d142d6c276, < 5feef67b646d8f5064bac288e22204ffba2b9a4a, >= a0285236ab93fdfdd1008afaa04561d142d6c276, < df445969aa727cd64f3f29dc1f85fb60aca238d1CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.