CVE-2025-40239 addresses a NULL pointer dereference vulnerability in the Linux kernel's LAN8814 Ethernet PHY driver. This flaw occurs because the shared->phydev pointer is not consistently initialized during the PTP probe, leading to a kernel crash when the IRQ handler attempts to use an unassigned pointer. The vulnerability has a FAUCET Risk Score of 7/100, indicating a low severity, and its impact is limited to system availability due to a denial-of-service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.10CNA affecteddefault affected | |
| Linux | Linux | >= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < 399d10934740ae8cdaa4e3245f7c5f6c332da844, >= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < b093b06826b836c2824858669db080c190c04715, >= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < da1ef8e9eb5d4a12bec32d11636e521e7d529b9eCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.