CVE-2025-40348 is a race condition vulnerability in the Linux kernel's slab allocator, specifically within the alloc_slab_obj_exts function. It allows competing threads to overwrite a valid slab->obj_exts pointer with a NULL value, leading to a subsequent null pointer dereference. While no CVSS score is provided, the FAUCET Risk Score is low at 7/100, indicating a limited potential impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.12.54, < 6.12.56CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.17.4, < 6.17.6CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
No media coverage found for this CVE.