CVE-2025-40060 Details
Description
In the Linux kernel, the following vulnerability has been resolved: coresight: trbe: Return NULL pointer for allocation failures When the TRBE driver fails to allocate a buffer, it currently returns the error code "-ENOMEM". However, the caller etm_setup_aux() only checks for a NULL pointer, so it misses the error. As a result, the driver continues and eventually causes a kernel panic. Fix this by returning a NULL pointer from arm_trbe_alloc_buffer() on allocation failures. This allows that the callers can properly handle the failure.
A vulnerability in the Linux kernel's Coresight TRBE driver can lead to a NULL pointer dereference and subsequent kernel panic. The issue arises when the driver fails to allocate a buffer. Instead of properly signaling the error, the driver returns an error code that is not checked by the caller. This oversight allows the driver to continue operating, ultimately causing a kernel panic. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been addressed in the Linux kernel. Users can upgrade to the latest version of the stable kernel to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/296da78494633e1ab5e2e74173a9c8683b04aa6b | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/8a55c161f7f9c1aa1c70611b39830d51c83ef36d | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/9768536f82600a05ce901e31ccfabd92c027ff71 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/cef047e0a55cb07906fcaae99170f19a9c0bb6c2 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f505a165f1c7cd37b4cb6952042a5984693a4067 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/fe53a726d5edf864e80b490780cc135fc1adece9 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
| ARM Coresight TRBE | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 28, 2025 | New CVE Received | kernel.org |
Volerion