CVE-2025-40116

Source
https://cve.org/CVERecord?id=CVE-2025-40116
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40116.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40116
Aliases
Downstream
Related
Published
2025-11-12T10:23:17.569Z
Modified
2026-01-14T18:56:42.542740Z
Summary
usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup

The kthreadrun() function returns error pointers so the max3421hcd->spi_thread pointer can be either error pointers or NULL. Check for both before dereferencing it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40116.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
05dfa5c9bc37933181b619e42ec0eeb41ef31362
Fixed
89838fe5c6c010ff8d3924f22afd9c18c5c95310
Fixed
3facf69a735e730ae36387f18780fe420708aa91
Fixed
e0e0ce06f3571be9b26790e4df56ba37b1de8543
Fixed
3723c3dda1cc82c9bbca08fcbd46705a361bfd56
Fixed
b0439e3762ac9ea580f714e1504a1827d1ad32f5
Fixed
e68ea6de1d0551f90d7a2c75f82cb3ebe5e397dc
Fixed
b682ce44bf20ada752a2f6ce70d5a575c56f6a35
Fixed
186e8f2bdba551f3ae23396caccd452d985c23e3

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40116.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.16.0
Fixed
5.4.301
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.246
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.195
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.156
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.112
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.53
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.3

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40116.json"