Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40348

10
FAUCET Score

CVE-2025-40348 is a race condition vulnerability in the Linux kernel's slab allocator, specifically within the alloc_slab_obj_exts function. It allows competing threads to overwrite a valid slab->obj_exts pointer with a NULL value, leading to a subsequent null pointer dereference. While no CVSS score is provided, the FAUCET Risk Score is low at 7/100, indicating a limited potential impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.12.54, < 6.12.56CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.17.4, < 6.17.6CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

No social media mentions found for this CVE.

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Patches (7)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2025-40348Important

kernel: slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts

Dec 16, 2025

References

git.kernel.org / stable/c/6ed8bfd24ce1cb31742b09a3eb557cd008533eec
git.kernel.org / stable/c/7c34feda6a9a203c9744281f1b6671b7dad2012d
git.kernel.org / stable/c/c7af5300d78460fc5037ddc77113ba3dbfe77dc0