CVE-2025-40030
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: check the return value of pinmux_ops::get_function_name()
While the API contract in docs doesn't specify it explicitly, the generic implementation of the get_function_name() callback from struct pinmux_ops - pinmux_generic_get_function_name() - can fail and return NULL. This is already checked in pinmux_check_ops() so add a similar check in pinmux_func_name_to_selector() instead of passing the returned pointer right down to strcmp() where the NULL can get dereferenced. This is normal operation when adding new pinfunctions.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a
- https://git.kernel.org/stable/c/1a7fc8fed2bb2e113604fde7a45432ace2056b97
- https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603
- https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b
- https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a
- https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e
- https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3
- https://git.kernel.org/stable/c/e7265dc4c670b89611bcf5fe33acf99bc0aa294f
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40030",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "1a7fc8fed2bb2e113604fde7a45432ace2056b97",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "e7265dc4c670b89611bcf5fe33acf99bc0aa294f",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "d77ef2f621cd1d605372c4c6ce667c496f6990c3",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "ba7f7c2b2b3261e7def67018c38c69b626e0e66e",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "1a2ea887a5cd7d47bab599f733d89444df018b1a",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "688c688e0bf55824f4a38f8c2180046f089a3e3b",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "b7e0535060a60cc99eafc19cc665d979714cd73a",
"versionType": "git"
},
{
"status": "affected",
"version": "f913cfce4ee49a3382a9ff95696f49a46e56e974",
"lessThan": "4002ee98c022d671ecc1e4a84029e9ae7d8a5603",
"versionType": "git"
}
],
"programFiles": [
"drivers/pinctrl/pinmux.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.4.301",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.246",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.195",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.156",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.112",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.53",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/pinctrl/pinmux.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-10-28T12:15:36.757",
"references": [
{
"url": "https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1a7fc8fed2bb2e113604fde7a45432ace2056b97",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e7265dc4c670b89611bcf5fe33acf99bc0aa294f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: check the return value of pinmux_ops::get_function_name()\n\nWhile the API contract in docs doesn't specify it explicitly, the\ngeneric implementation of the get_function_name() callback from struct\npinmux_ops - pinmux_generic_get_function_name() - can fail and return\nNULL. This is already checked in pinmux_check_ops() so add a similar\ncheck in pinmux_func_name_to_selector() instead of passing the returned\npointer right down to strcmp() where the NULL can get dereferenced. This\nis normal operation when adding new pinfunctions."
}
],
"lastModified": "2026-06-17T09:21:08.970",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}