Junglewise Threat Intelligence

CVE-2025-40070: Linux Kernel double free in PPS device registration

CVE-2025-40070 · Severity: info · CVSS 3.3 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Pulse Per Second (PPS) subsystem, which is used for high-precision time synchronization. Under specific error conditions during device registration, the system may trigger a kernel warning or experience a 'double free' memory error. This could lead to a system crash or instability, potentially impacting the availability of services relying on precise timing.

Technical details

A vulnerability exists in the Linux kernel PPS (Pulse Per Second) subsystem due to improper ordering of device registration and release hook assignment. In `pps_register_cdev`, the `release` hook was being set after `device_register()`. If `device_register()` fails, the subsequent `put_device()` call triggers a kernel warning because the release function is missing. Additionally, a double-free vulnerability existed in `pps_register_source()` where `kfree_pps` was incorrectly called during failure cases. An attacker with local access could potentially trigger these error paths to cause a Denial of Service (DoS) via kernel panic. The fix ensures the release hook is set before registration and removes the redundant kfree call.

Affected products

  • Linux Linux Kernel 6.17.0-rc3+; V3.1.6 (Siemens SIMATIC)

Timeline

  • 2025-08-30: patched: Initial patch authored by Wang Liang
  • 2025-10-28: advisory: CVE published

References

Related threats