Wind River Support Network

HomeDefectsLIN1025-5913
Fixed

LIN1025-5913 : Security Advisory - linux - CVE-2025-40177

Created: Nov 12, 2025    Updated: Nov 25, 2025
Resolved Date: Nov 24, 2025
Found In Version: 10.25.33.1
Fix Version: 10.25.33.3
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]accel/qaic: Fix bootlog initialization ordering[EOL][EOL]As soon as we queue MHI buffers to receive the bootlog from the device,[EOL]we could be receiving data. Therefore all the resources needed to[EOL]process that data need to be setup prior to queuing the buffers.[EOL][EOL]We currently initialize some of the resources after queuing the buffers[EOL]which creates a race between the probe() and any data that comes back[EOL]from the device. If the uninitialized resources are accessed, we could[EOL]see page faults.[EOL][EOL]Fix the init ordering to close the race.

CVEs


Live chat
Online