SB2025102899 - NULL pointer dereference in Linux kernel hwtracing coresight driver
Published: October 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-40060)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the arm_trbe_alloc_buffer() function in drivers/hwtracing/coresight/coresight-trbe.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/296da78494633e1ab5e2e74173a9c8683b04aa6b
- https://git.kernel.org/stable/c/8a55c161f7f9c1aa1c70611b39830d51c83ef36d
- https://git.kernel.org/stable/c/9768536f82600a05ce901e31ccfabd92c027ff71
- https://git.kernel.org/stable/c/cef047e0a55cb07906fcaae99170f19a9c0bb6c2
- https://git.kernel.org/stable/c/f505a165f1c7cd37b4cb6952042a5984693a4067
- https://git.kernel.org/stable/c/fe53a726d5edf864e80b490780cc135fc1adece9