Resource management error in Linux kernel - CVE-2025-40108
Published: November 10, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the geni_serial_set_rate(), qcom_geni_serial_set_termios(), geni_serial_resources_off(), qcom_geni_serial_pm(), qcom_geni_serial_probe(), qcom_geni_serial_remove() and qcom_geni_serial_resume() functions in drivers/tty/serial/qcom_geni_serial.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
linux-raspi (Ubuntu package)
How to mitigate CVE-2025-40108
linux-gcp (Ubuntu package) - update to 6.17.0-1004.4
linux-raspi (Ubuntu package) - update to 6.17.0-1005.5