CVE-2025-40296 describes a double-free vulnerability in the Linux kernel's int3472 platform driver, specifically affecting ThinkPad X9 (Lunar Lake) devices. This flaw occurs during regulator unregistration, where the GPIO device is erroneously freed twice, leading to system instability and random failures when other drivers attempt interrupt allocation. While no CVSS score is provided, the issue is internal to the kernel and does not have a direct attack vector from an external source. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.16CNA affecteddefault affected | |
| Linux | Linux | >= 1e5d088a52c207bcef6a43a6f6ffe162c514ed64, < b8113bb56c45bd17bac5144b55591f9cdbd6aabe, >= 1e5d088a52c207bcef6a43a6f6ffe162c514ed64, < f0f7a3f542c1698edb69075f25a3f846207facbaCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.