CVE-2025-40249 addresses a use-after-free vulnerability in the Linux kernel's GPIO character device driver. Specifically, it prevents a situation where GPIO change events could be emitted to a file descriptor that is in the process of being released, leading to a warning and potential system instability. This vulnerability affects the Linux kernel and does not have a CVSS score, but its FAUCET Risk Score is 7/100, indicating a low to moderate risk. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.13CNA affecteddefault affected | |
| Linux | Linux | >= 40b7c49950bd56c984b1f6722f865b922879260e, < d4cd0902c156b2ca60fdda8cd8b5bcb4b0e9ed64, >= 40b7c49950bd56c984b1f6722f865b922879260e, < dccc6daa8afa0f64c432e4c867f275747e3415e1CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service
Dec 4, 2025