CVE-2025-40226 Details
Description
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Account for failed debug initialization When the SCMI debug subsystem fails to initialize, the related debug root will be missing, and the underlying descriptor will be NULL. Handle this fault condition in the SCMI debug helpers that maintain metrics counters.
A vulnerability exists in the Linux kernel's SCMI (System Control and Management Interface) debug subsystem. When the debug subsystem fails to initialize, it results in a missing debug root and a NULL descriptor. This issue affects the SCMI debug helpers responsible for maintaining metrics counters, leading to improper handling of debug information. The vulnerability has been addressed in the Linux kernel stable tree.
Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2290ab43b9d8eafb8046387f10a8dfa2b030ba46 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/554c9d5c6c695aedaecfb4365c187102709397b0 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/d719ce9f286c439795cd2beee4c91f12b84bc5a0 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/e088efcd97cb7c7297d166bb52c3b87a29f6a0b1 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
| arm_scmi | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 4, 2025 | New CVE Received | kernel.org |
Volerion