CVE-2025-40060
Published Oct 28, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: coresight: trbe: Return NULL pointer for allocation failures When the TRBE driver fails to allocate a buffer, it currently returns the error code "-ENOMEM". However, the caller etm_setup_aux() only checks for a NULL pointer, so it misses the error. As a result, the driver continues and eventually causes a kernel panic. Fix this by returning a NULL pointer from arm_trbe_alloc_buffer() on allocation failures. This allows that the callers can properly handle the failure.
Is your site exposed to CVE-2025-40060?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/296da78494633e1ab5e2e74173a9c8683b04aa6b
https://git.kernel.org/stable/c/8a55c161f7f9c1aa1c70611b39830d51c83ef36d
https://git.kernel.org/stable/c/9768536f82600a05ce901e31ccfabd92c027ff71
https://git.kernel.org/stable/c/cef047e0a55cb07906fcaae99170f19a9c0bb6c2
https://git.kernel.org/stable/c/f505a165f1c7cd37b4cb6952042a5984693a4067
https://git.kernel.org/stable/c/fe53a726d5edf864e80b490780cc135fc1adece9
Frequently Asked Questions
What is CVE-2025-40060? +
In the Linux kernel, the following vulnerability has been resolved:
coresight: trbe: Return NULL pointer for allocation failures
When the TRBE driver fails to allocate a buffer, it currently returns
the error code "-ENOMEM". However, the caller etm_setup_aux() only
checks for a NULL pointer, so it misses the error. As a result, the
driver continues and eventually causes a kernel panic.
Fix this by returning a NULL pointer from arm_trbe_alloc_buffer() on
allocation failures. This allows that the callers can properly handle
the failure.
How do I check if I'm vulnerable to CVE-2025-40060? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.