Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40189

10
FAUCET Score

CVE-2025-40189 describes a vulnerability in the Linux kernel's lan78xx USB network driver, specifically affecting how it handles EEPROM read timeout errors. The driver failed to properly propagate these errors, leading to the use of uninitialized data in subsequent operations, as reported by Syzbot. This could result in system instability or unexpected behavior, though the attack vector and complexity are not fully detailed. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.14CNA affecteddefault affected
LinuxLinux
>= 8b1b2ca83b200fa46fdfb81e80ad5fe34537e6d4, < 49bdb63ff64469a6de8ea901aef123c75be9bbe7, >= 8b1b2ca83b200fa46fdfb81e80ad5fe34537e6d4, < a72a7c4f675080a324d4c2167bd2314d968279f1CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

No social media mentions found for this CVE.

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (1)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40189

kernel: net: usb: lan78xx: Fix lost EEPROM read timeout error(-ETIMEDOUT) in lan78xx_read_raw_eeprom

Nov 12, 2025

References

git.kernel.org / stable/c/49bdb63ff64469a6de8ea901aef123c75be9bbe7
git.kernel.org / stable/c/a72a7c4f675080a324d4c2167bd2314d968279f1