CVE-2025-40130 describes a data race vulnerability in the Linux kernel's SCSI UFS core, specifically within the CPU latency PM QoS request handling. This flaw, affecting the management of power management quality of service, can lead to list corruption and use-after-free issues due to insufficient synchronization. While no CVSS score is provided, its FAUCET Risk Score is 5/100, indicating a low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.9CNA affecteddefault affected | |
| Linux | Linux | >= 2777e73fc154e2e87233bdcc0e2402b33815198e, < 79dde5f7dc7c038eec903745dc1550cd4139980e, >= 2777e73fc154e2e87233bdcc0e2402b33815198e, < d9df61afb8d23c475f1be3c714da2c34c156ab01CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.