CVE-2025-40144 Details
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
A vulnerability in the Linux kernel's nvdimm testing framework can lead to a NULL pointer dereference. This issue arises in the ndtest_probe function, which allocates three DMA address arrays. If the memory allocation fails, the function does not properly handle the error, allowing for a NULL pointer dereference under low-memory conditions. The vulnerability has been addressed by modifying the allocation process to check for errors and return an appropriate memory allocation failure response, thereby preventing the NULL pointer dereference.
Users can update to the latest version of the Linux kernel, where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux documentation or through the package management system of the Linux distribution in use.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Nov 21, 2025 | CVE Rejected | kernel.org |
| Nov 21, 2025 | CVE Modified | kernel.org |
| Nov 12, 2025 | New CVE Received | kernel.org |