« Volver al listado

CVE-2025-40060

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

coresight: trbe: Return NULL pointer for allocation failures

When the TRBE driver fails to allocate a buffer, it currently returns the error code "-ENOMEM". However, the caller etm_setup_aux() only checks for a NULL pointer, so it misses the error. As a result, the driver continues and eventually causes a kernel panic.

Fix this by returning a NULL pointer from arm_trbe_alloc_buffer() on allocation failures. This allows that the callers can properly handle the failure.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40060",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "cef047e0a55cb07906fcaae99170f19a9c0bb6c2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "fe53a726d5edf864e80b490780cc135fc1adece9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "9768536f82600a05ce901e31ccfabd92c027ff71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "296da78494633e1ab5e2e74173a9c8683b04aa6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "f505a165f1c7cd37b4cb6952042a5984693a4067",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3fbf7f011f2426dac8c982f1d2ef469a7959a524",
              "lessThan": "8a55c161f7f9c1aa1c70611b39830d51c83ef36d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hwtracing/coresight/coresight-trbe.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.195",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hwtracing/coresight/coresight-trbe.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-28T12:15:40.377",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/296da78494633e1ab5e2e74173a9c8683b04aa6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8a55c161f7f9c1aa1c70611b39830d51c83ef36d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9768536f82600a05ce901e31ccfabd92c027ff71",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cef047e0a55cb07906fcaae99170f19a9c0bb6c2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f505a165f1c7cd37b4cb6952042a5984693a4067",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fe53a726d5edf864e80b490780cc135fc1adece9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: trbe: Return NULL pointer for allocation failures\n\nWhen the TRBE driver fails to allocate a buffer, it currently returns\nthe error code \"-ENOMEM\". However, the caller etm_setup_aux() only\nchecks for a NULL pointer, so it misses the error. As a result, the\ndriver continues and eventually causes a kernel panic.\n\nFix this by returning a NULL pointer from arm_trbe_alloc_buffer() on\nallocation failures. This allows that the callers can properly handle\nthe failure."
    }
  ],
  "lastModified": "2026-06-17T09:21:11.917",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}