Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40029— bus: fsl-mc: Check return value of platform_get_resource()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查platform_get_resource返回值,可能导致空指针取消引用。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 6305166c8771c33a8d5992fb53f93cfecedc14fd< 58dd05070b57a20f22ff35a34ef9846bdf49a1d0 affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< 8a4dd74fe413d4a278e649be1d22d028e1667116 affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< e60d55692e6c8e951000343c39f3fc92cab57efc affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< 78e87b8a3cf8a59671ea25c87192d16e8d710e1c affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< 84ec0482ed9c9ed0aee553a5e7e7458ad79c021f affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< 2ead548473f58c7960b6b939b79503c4a0a2c0bd affected
6305166c8771c33a8d5992fb53f93cfecedc14fd< 25f526507b8ccc6ac3a43bc094d09b1f9b0b90ae affected
5.9 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-40029

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bus: fsl-mc: Check return value of platform_get_resource()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: Check return value of platform_get_resource() platform_get_resource() returns NULL in case of failure, so check its return value and propagate the error in order to prevent NULL pointer dereference.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查platform_get_resource返回值,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 6305166c8771c33a8d5992fb53f93cfecedc14fd ~ 58dd05070b57a20f22ff35a34ef9846bdf49a1d0 -
Linux Linux 5.9 -

II. Public POCs for CVE-2025-40029

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40029

登录查看更多情报信息。

Patches & Fixes for CVE-2025-40029 (2)

Same Patch Batch · Linux · 2025-10-28 · 58 CVEs total

CVE-2025-40074 9.8 CRITICAL ipv4: start using dst_dev_rcu()
CVE-2025-40043 8.8 HIGH net: nfc: nci: Add parameter validation for packet data
CVE-2025-40039 8.8 HIGH ksmbd: Fix race condition in RPC handle list access
CVE-2025-40058 8.8 HIGH iommu/vt-d: Disallow dirty tracking if incoherent page walk
CVE-2025-40046 8.6 HIGH io_uring/zcrx: fix overshooting recv limit
CVE-2025-40068 8.4 HIGH fs: ntfs3: Fix integer overflow in run_unpack()
CVE-2025-40075 8.1 HIGH tcp_metrics: use dst_dev_net_rcu()
CVE-2025-40026 7.9 HIGH KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
CVE-2025-40027 7.8 HIGH net/9p: fix double req put in p9_fd_cancelled
CVE-2025-40054 7.8 HIGH f2fs: fix UAF issue in f2fs_merge_page_bio()
CVE-2025-40045 7.8 HIGH ASoC: codecs: wcd937x: set the comp soundwire port correctly
CVE-2025-40047 7.8 HIGH io_uring/waitid: always prune wait queue entry in io_waitid_wait()
CVE-2025-40051 7.8 HIGH vhost: vringh: Modify the return value check
CVE-2025-40025 7.8 HIGH f2fs: fix to do sanity check on node footer for non inode dnode
CVE-2025-40061 7.8 HIGH RDMA/rxe: Fix race in do_task() when draining
CVE-2025-40064 7.8 HIGH smc: Fix use-after-free in __pnet_find_base_ndev().
CVE-2025-40067 7.8 HIGH fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist
CVE-2025-40069 7.8 HIGH drm/msm: Fix obj leak in VM_BIND error path
CVE-2025-40079 7.8 HIGH riscv, bpf: Sign extend struct ops return values properly
CVE-2025-40081 7.8 HIGH perf: arm_spe: Prevent overflow in PERF_IDX2OFF()

Showing top 20 of 58 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40029

No comments yet


Leave a comment