CVE-2025-40030
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: pinctrl: check the return value of pinmux_ops::get_function_name() While the API contract in docs doesn't specify it explicitly, the generic implementation of the get_function_name() callback from struct pinmux_ops - pinmux_generic_get_function_name() - can fail and return NULL. This is already checked in pinmux_check_ops() so add a similar check in pinmux_func_name_to_selector() instead of passing the returned pointer right down to strcmp() where the NULL can get dereferenced. This is normal operation when adding new pinfunctions.
EPSS Trends
Current EPSS score: 0.21%• Percentile: 12%
Affected Systems
- debian•linux
< 5.10.247-1 | < 6.1.158-1 | < 6.12.57-1 | < 6.17.6-1
- debian•linux-6.1
< 6.1.158-1~deb11u1
- ubuntu•linux
all | < 5.15.0-170.180 | < 6.8.0-106.106 | < 6.17.0-14.14
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | < 5.15.0-1100.107 | < 6.8.0-1050.53 | < 6.17.0-1007.7
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1100.107~20.04.2
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
all
- ubuntu•linux-aws-6.17
< 6.17.0-1007.7~24.04.1
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1050.53~22.04.1
- ubuntu•linux-aws-fips
all | < 5.15.0-1100.107+fips1 | < 6.8.0-1050.53+fips1
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | < 5.15.0-1109.118 | < 6.8.0-1051.57 | < 6.17.0-1008.8
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1110.119~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.14
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1051.57~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.14
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
all | < 5.15.0-1109.118+fips1 | < 6.8.0-1052.58+fips1
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-azure-nvidia-6.14
all
- ubuntu•linux-bluefield
all | all | < 5.15.0-1084.86 | < 6.8.0-1017.21
- ubuntu•linux-fips
all | < 5.15.0-170.180+fips1 | < 6.8.0-106.106+fips1
- ubuntu•linux-gcp
all | all | < 5.15.0-1100.109 | < 6.8.0-1052.55 | < 6.17.0-1007.7
- ubuntu•linux-gcp-4.15
all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
Showing first 50 affected entries in server-rendered view.
References (41)
- https://git.kernel.org/stable/c/1a7fc8fed2bb2e113604fde7a45432ace2056b97
- https://git.kernel.org/stable/c/e7265dc4c670b89611bcf5fe33acf99bc0aa294f
- https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3
- https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e
- https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a
- https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b
- https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a
- https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603
- https://ubuntu.com/security/CVE-2025-40030
- https://www.cve.org/CVERecord?id=CVE-2025-40030
- https://git.kernel.org/linus/4002ee98c022d671ecc1e4a84029e9ae7d8a5603
- https://ubuntu.com/security/notices/USN-8029-1
- https://ubuntu.com/security/notices/USN-8030-1
- https://ubuntu.com/security/notices/USN-8033-1
- https://ubuntu.com/security/notices/USN-8033-2
- https://ubuntu.com/security/notices/USN-8033-3
- https://ubuntu.com/security/notices/USN-8034-1
- https://ubuntu.com/security/notices/USN-8033-4
- https://ubuntu.com/security/notices/USN-8029-2
- https://ubuntu.com/security/notices/USN-8033-5
- https://ubuntu.com/security/notices/USN-8034-2
- https://ubuntu.com/security/notices/USN-8048-1
- https://ubuntu.com/security/notices/USN-8033-6
- https://ubuntu.com/security/notices/USN-8033-7
- https://ubuntu.com/security/notices/USN-8033-8
- https://ubuntu.com/security/notices/USN-8029-3
- https://ubuntu.com/security/notices/USN-8095-1
- https://ubuntu.com/security/notices/USN-8100-1
- https://ubuntu.com/security/notices/USN-8095-2
- https://ubuntu.com/security/notices/USN-8095-3
- https://ubuntu.com/security/notices/USN-8095-4
- https://ubuntu.com/security/notices/USN-8125-1
- https://ubuntu.com/security/notices/USN-8126-1
- https://ubuntu.com/security/notices/USN-8095-5
- https://ubuntu.com/security/notices/USN-8141-1
- https://ubuntu.com/security/notices/USN-8163-1
- https://ubuntu.com/security/notices/USN-8165-1
- https://ubuntu.com/security/notices/USN-8163-2
- https://ubuntu.com/security/notices/USN-8243-1
- https://ubuntu.com/security/notices/USN-8261-1
- https://security-tracker.debian.org/tracker/CVE-2025-40030