已关闭
CVE-2025-40030 #12323
openeuler-ci-bot创建于  2025年10月28日关闭于  4月9日
openeuler-ci-bot
openeuler-ci-bot成员
2025年10月28日 创建

一、漏洞信息
漏洞编号:CVE-2025-40030
漏洞归属组件:kernel
漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.19,6.4.0,6.6.0
CVSS评分:
BaseScore:N/A None
Vector:
漏洞简述:
In the Linux kernel, the following vulnerability has been resolved:pinctrl: check the return value of pinmux_ops::get_function_name()While the API contract in docs doesn t specify it explicitly, thegeneric implementation of the get_function_name() callback from structpinmux_ops - pinmux_generic_get_function_name() - can fail and returnNULL. This is already checked in pinmux_check_ops() so add a similarcheck in pinmux_func_name_to_selector() instead of passing the returnedpointer right down to strcmp() where the NULL can get dereferenced. Thisis normal operation when adding new pinfunctions.
漏洞公开时间:2025-10-28 20:15:36
漏洞创建时间:2025-10-28 20:56:02
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2025-40030

更多参考(点击展开)
参考来源 参考链接 来源链接
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.115
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.111
https://linux.oracle.com/cve/CVE-2025-40030.html
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.109
https://bugs.mageia.org/show_bug.cgi?id=34721
https://nvd.nist.gov/vuln/detail/CVE-2025-40030
https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603
https://advisories.mageia.org/MGASA-2025-0309.html
https://lore.kernel.org/linux-cve-announce/2025102810-CVE-2025-40030-b395@gregkh/T
https://linux.oracle.com/errata/ELSA-2025-28049.html
https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a
https://git.kernel.org/stable/c/e7265dc4c670b89611bcf5fe33acf99bc0aa294f
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.108
https://lore.kernel.org/linux-cve-announce/2025102810-CVE-2025-40030-b395@gregkh/T/#u
https://bugzilla.redhat.com/show_bug.cgi?id=2406728
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.110
https://linux.oracle.com/errata/ELSA-2025-28040.html
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.114
https://security-tracker.debian.org/tracker/CVE-2025-40030
https://git.kernel.org/stable/c/1a7fc8fed2bb2e113604fde7a45432ace2056b97
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.106
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.116
https://linux.oracle.com/errata/ELSA-2025-28048.html
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.112
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-40030
https://advisory.echohq.com/cve/CVE-2025-40030
https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a
https://advisories.mageia.org/MGASA-2025-0310.html
https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3
https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e
https://www.cve.org/CVERecord?id=CVE-2025-40030
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.113
https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b
https://bugs.mageia.org/show_bug.cgi?id=34713
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.107

漏洞分析指导链接:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
七彩瞬析开源风险感知平台
漏洞补丁信息:

详情(点击展开)
影响的包 修复版本 修复补丁 问题引入补丁 来源
gregkh/linux https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3 ljqc
gregkh/linux https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e ljqc
gregkh/linux https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a ljqc
gregkh/linux https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b ljqc
gregkh/linux https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a ljqc
gregkh/linux https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603 ljqc
https://git.kernel.org/stable/c/4002ee98c022d671ecc1e4a84029e9ae7d8a5603 cvelistv5
https://git.kernel.org/stable/c/1a2ea887a5cd7d47bab599f733d89444df018b1a cvelistv5
https://git.kernel.org/stable/c/e7265dc4c670b89611bcf5fe33acf99bc0aa294f cvelistv5
https://git.kernel.org/stable/c/1a7fc8fed2bb2e113604fde7a45432ace2056b97 cvelistv5
https://git.kernel.org/stable/c/b7e0535060a60cc99eafc19cc665d979714cd73a cvelistv5
https://git.kernel.org/stable/c/d77ef2f621cd1d605372c4c6ce667c496f6990c3 cvelistv5
https://git.kernel.org/stable/c/ba7f7c2b2b3261e7def67018c38c69b626e0e66e cvelistv5
https://git.kernel.org/stable/c/688c688e0bf55824f4a38f8c2180046f089a3e3b cvelistv5

二、漏洞分析结构反馈
影响性分析说明:
In the Linux kernel, the following vulnerability has been resolved:pinctrl: check the return value of pinmux_ops::get_function_name()While the API contract in docs doesn't specify it explicitly, thegeneric implementation of the get_function_name() callback from structpinmux_ops - pinmux_generic_get_function_name() - can fail and returnNULL. This is already checked in pinmux_check_ops() so add a similarcheck in pinmux_func_name_to_selector() instead of passing the returnedpointer right down to strcmp() where the NULL can get dereferenced. Thisis normal operation when adding new pinfunctions.The Linux kernel CVE team has assigned CVE-2025-40030 to this issue.
openEuler评分:
5.5
Vector:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
受影响版本排查(受影响/不受影响):
1.master(6.12.33):不受影响
2.openEuler-20.03-LTS-SP4(4.19.90):受影响
3.openEuler-22.03-LTS-SP3(5.10.0):受影响
4.openEuler-22.03-LTS-SP4(5.10.0):受影响
5.openEuler-24.03-LTS(6.6.0):受影响
6.openEuler-24.03-LTS-Next(6.6.0):不受影响
7.openEuler-24.03-LTS-SP1(6.6.0):受影响
8.openEuler-24.03-LTS-SP2(6.6.0):受影响
9.openEuler-24.03-LTS-SP3(6.6.0):不受影响

修复是否涉及abi变化(是/否):
1.master(6.12.33):否
2.openEuler-20.03-LTS-SP4(4.19.90):否
3.openEuler-22.03-LTS-SP3(5.10.0):否
4.openEuler-22.03-LTS-SP4(5.10.0):否
5.openEuler-24.03-LTS(6.6.0):否
6.openEuler-24.03-LTS-Next(6.6.0):否
7.openEuler-24.03-LTS-SP1(6.6.0):否
8.openEuler-24.03-LTS-SP2(6.6.0):否
9.openEuler-24.03-LTS-SP3(6.6.0):否

原因说明:
1.master(6.12.33):不受影响-漏洞代码不能被攻击者触发
2.openEuler-20.03-LTS-SP4(4.19.90):不修复-超出修复范围
3.openEuler-22.03-LTS-SP3(5.10.0):不修复-超出修复范围
4.openEuler-22.03-LTS-SP4(5.10.0):不修复-超出修复范围
5.openEuler-24.03-LTS(6.6.0):正常修复
6.openEuler-24.03-LTS-Next(6.6.0):不受影响-漏洞代码不能被攻击者触发
7.openEuler-24.03-LTS-SP1(6.6.0):正常修复
8.openEuler-24.03-LTS-SP2(6.6.0):正常修复
9.openEuler-24.03-LTS-SP3(6.6.0):不受影响-漏洞代码不能被攻击者触发

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2025年10月28日 创建了CVE和安全问题
openeuler-ci-botopeneuler-ci-bot成员
2025年10月28日 添加了   sig/Kernel 标签
openeuler-ci-botopeneuler-ci-bot成员
2025年10月28日 修改了描述
openeuler-ci-botopeneuler-ci-bot成员
2025年10月28日 修改了描述
openeuler-ci-botopeneuler-ci-bot成员
2025年10月29日 修改了描述
此处折叠了101条消息 查看更多
openeuler-ci-botopeneuler-ci-bot成员
1月31日 issue状态由 待办的 改变为 进行中
openeuler-ci-botopeneuler-ci-bot成员
4月9日 关闭了 issue
openeuler-ci-botopeneuler-ci-bot成员
4月9日 issue状态由 进行中 改变为 已完成
openeuler-ci-botopeneuler-ci-bot成员
4月9日 删除了label:CVE/UNFIXED
openeuler-ci-botopeneuler-ci-bot成员
4月9日 添加了label:CVE/FIXED