CVE-2025-40201 addresses a race condition in the Linux kernel's sys_prlimit64() function, specifically concerning the usage of task_lock(tsk->group_leader). This flaw could lead to the use of freed memory or incorrect locking if the target process exits, executes a new program, or undergoes a multithreaded execution change. While a CVSS score is not available, its FAUCET Risk Score is low at 5/100, and its EPSS score is also very low, indicating a minimal likelihood of exploitation. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.18CNA affecteddefault affected | |
| Linux | Linux | >= 18c91bb2d87268d23868bf13508f5bc9cf04e89a, < 132f827e7bac7373e1522e89709d70b43cae5342, >= 18c91bb2d87268d23868bf13508f5bc9cf04e89a, < 19b45c84bd9fd42fa97ff80c6350d604cb871c75, >= 18c91bb2d87268d23868bf13508f5bc9cf04e89a, < 1bc0d9315ef5296abb2c9fd840336255850ded18, >= 18c91bb2d87268d23868bf13508f5bc9cf04e89a, < 6796412decd2d8de8ec708213bbc958fab72f143, >= 18c91bb2d87268d23868bf13508f5bc9cf04e89a, < a15f37a40145c986cdf289a4b88390f35efdecc4CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026kernel: kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
Nov 12, 2025kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
Nov 11, 2025