CVE-2025-40226: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Account for failed debug initialization When the SCMI debug subsystem fails to initialize, the related debug root will be missing, and the underlying descriptor will be NULL. Handle this fault condition in the SCMI debug helpers that maintain metrics counters.

Affected products

  • Linux Linux: from 6.6.92, before 6.6.115 (fixed in 6.6.115); from 6.12, before 6.12.56 (fixed in 6.12.56); from 6.13, before 6.17.6 (fixed in 6.17.6)

Published 2025-12-04. Last modified 2026-06-17.