NULL pointer dereference in Linux kernel - CVE-2025-40290
Published: December 8, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the xsk_cq_reserve_locked(), xsk_cq_cancel_locked(), xsk_destruct_skb(), xsk_build_skb_zerocopy(), xsk_build_skb() and xsk_init() functions in net/xdp/xsk.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-6.17 (Ubuntu package)
linux-realtime-6.17 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
How to mitigate CVE-2025-40290
linux-gcp-6.17 (Ubuntu package) - addressed in versions 6.17.0-1008.9, 6.17.0-1009.9~24.04.3
linux-realtime-6.17 (Ubuntu package) - update to 6.17.0-1008.9~24.04.1
linux-azure (Ubuntu package) - addressed in versions 6.17.0-1010.10, 6.17.0-1010.10~24.04.1
linux-raspi (Ubuntu package) - update to 6.17.0-1010.10
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1017.17