CVE-2025-40147 describes a NULL pointer dereference vulnerability in the Linux kernel's block layer throttling mechanism. This flaw can occur during repeated cold boots when the throttle policy is consulted before being fully enabled, leading to a system crash. While no CVSS score is available, the vulnerability's impact is a denial of service due to system instability. There is no indication of active exploitation, public exploit code, or significant community discussion beyond a single security update notice.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.10CNA affecteddefault affected | |
| Linux | Linux | >= a3166c51702bb00b8f8b84022090cbab8f37be1a, < 6a0c394300a7b0c05504596685de8a46707171fc, >= a3166c51702bb00b8f8b84022090cbab8f37be1a, < 7b4bfd02c934dbbb18814ed012ecb90b58db6935, >= a3166c51702bb00b8f8b84022090cbab8f37be1a, < bd9fd5be6bc0836820500f68fff144609fbd85a9CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.