CVE-2025-40255 describes a NULL pointer dereference vulnerability in the Linux kernel's networking subsystem, specifically within the generic_hwtstamp_ioctl_lower() function. This flaw can be triggered via the ethtool tsconfig Netlink path, leading to a system crash. The vulnerability has no assigned CVSS score, but its potential to cause a denial of service gives it a FAUCET Risk Score of 7/100. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.14CNA affecteddefault affected | |
| Linux | Linux | >= 6e9e2eed4f39d52edf5fd006409d211facf49f6b, < 8817f816ae41908e9625c0770c4af0dcdcc01238, >= 6e9e2eed4f39d52edf5fd006409d211facf49f6b, < f796a8dec9beafcc0f6f0d3478ed685a15c5e062CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower()
Dec 4, 2025