PT-2025-44381 · Linux+4 · Linux Kernel+4
CVE-2025-40091
·
Published
2025-10-13
·
Updated
2026-03-07
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.17.0-rc2-tnguy.net-queue+
Description
A use-after-free issue exists in the Linux kernel's ixgbe driver. Specifically, the
devlink free() function is called prematurely within the ixgbe remove() path. This occurs because the ixgbe adapter is embedded within devlink, and freeing it too early can lead to a use-after-free condition. The issue was identified through a Kernel Address Sanitizer (KASAN) report during testing. The vulnerable function is ixgbe reset interrupt capability().Recommendations
Update to a version of the Linux kernel newer than 6.17.0-rc2-tnguy.net-queue+.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Suse
Ubuntu
Ixgbe Driver