Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40239

11
FAUCET Score

CVE-2025-40239 addresses a NULL pointer dereference vulnerability in the Linux kernel's LAN8814 Ethernet PHY driver. This flaw occurs because the shared->phydev pointer is not consistently initialized during the PTP probe, leading to a kernel crash when the IRQ handler attempts to use an unassigned pointer. The vulnerability has a FAUCET Risk Score of 7/100, indicating a low severity, and its impact is limited to system availability due to a denial-of-service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.10CNA affecteddefault affected
LinuxLinux
>= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < 399d10934740ae8cdaa4e3245f7c5f6c332da844, >= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < b093b06826b836c2824858669db080c190c04715, >= b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746, < da1ef8e9eb5d4a12bec32d11636e521e7d529b9eCNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (4)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40239Moderate

kernel: net: phy: micrel: always set shared->phydev for LAN8814

Dec 4, 2025

References

git.kernel.org / stable/c/399d10934740ae8cdaa4e3245f7c5f6c332da844
git.kernel.org / stable/c/b093b06826b836c2824858669db080c190c04715
git.kernel.org / stable/c/da1ef8e9eb5d4a12bec32d11636e521e7d529b9e