Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40102

12
FAUCET Score

CVE-2025-40102 describes a vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) for arm64 architectures. It allows userspace to pend vCPU events before the vCPU is properly initialized, leading to the KVM interpreting uninitialized data. This can result in a kernel bug and system crash, as demonstrated by a specific case where the vCPU enters an illegal mode. The severity is moderate, with a FAUCET Risk Score of 5/100. The attack vector involves specific KVM ioctls, and the complexity appears to be low given the direct manipulation of vCPU events. The potential impact is a denial of service due to a kernel crash. There is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
4.19CNA affecteddefault affected
LinuxLinux
>= b7b27facc7b50a5fce0afaa3df56157136ce181a, < 0aa1b76fe1429629215a7c79820e4b96233ac4a3, >= b7b27facc7b50a5fce0afaa3df56157136ce181a, < 64a04e6320fc5affbadc59dc7024d79f909bfe84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: FAUCET enrichment

N/A
User InteractionAI
NONE

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40102Moderate

kernel: Linux kernel KVM: Denial of Service due to uninitialized vCPU event handling

Oct 30, 2025
microsoft2025-Oct/CVE-2025-40102Important

KVM: arm64: Prevent access to vCPU events before init

Oct 14, 2025

References

git.kernel.org / stable/c/0aa1b76fe1429629215a7c79820e4b96233ac4a3
git.kernel.org / stable/c/64a04e6320fc5affbadc59dc7024d79f909bfe84