CVE-2025-40010

Source
https://cve.org/CVERecord?id=CVE-2025-40010
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40010.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40010
Downstream
Related
Published
2025-10-20T15:26:55.874Z
Modified
2026-03-20T12:43:08.580994Z
Summary
afs: Fix potential null pointer dereference in afs_put_server
Details

In the Linux kernel, the following vulnerability has been resolved:

afs: Fix potential null pointer dereference in afsputserver

afsputserver() accessed server->debugid before the NULL check, which could lead to a null pointer dereference. Move the debugid assignment, ensuring we never dereference a NULL server pointer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40010.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2757a4dc184997c66ef1de32636f73b9f21aac14
Fixed
7b8381f3c405b864a814d747e526e078c3ef4bc2
Fixed
cab278cead49a547ac84c3e185f446f381303eae
Fixed
a13dbc5e20c7284b82afe6f08debdecf51d2ca04
Fixed
41782c44bb8431c43043129ae42f2ba614938479
Fixed
9158c6bb245113d4966df9b2ba602197a379412e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40010.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.155
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.109
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.50
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40010.json"