CVE-2025-40189 describes a vulnerability in the Linux kernel's lan78xx USB network driver, specifically affecting how it handles EEPROM read timeout errors. The driver failed to properly propagate these errors, leading to the use of uninitialized data in subsequent operations, as reported by Syzbot. This could result in system instability or unexpected behavior, though the attack vector and complexity are not fully detailed. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.14CNA affecteddefault affected | |
| Linux | Linux | >= 8b1b2ca83b200fa46fdfb81e80ad5fe34537e6d4, < 49bdb63ff64469a6de8ea901aef123c75be9bbe7, >= 8b1b2ca83b200fa46fdfb81e80ad5fe34537e6d4, < a72a7c4f675080a324d4c2167bd2314d968279f1CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
No media coverage found for this CVE.