{"id":"DEBIAN-CVE-2025-40178","details":"In the Linux kernel, the following vulnerability has been resolved:  pid: Add a judgment for ns null in pid_nr_ns  __task_pid_nr_ns         ns = task_active_pid_ns(current);         pid_nr_ns(rcu_dereference(*task_pid_ptr(task, type)), ns);                 if (pid && ns-\u003elevel \u003c= pid-\u003elevel) {  Sometimes null is returned for task_active_pid_ns. Then it will trigger kernel panic in pid_nr_ns.  For example: \tUnable to handle kernel NULL pointer dereference at virtual address 0000000000000058 \tMem abort info: \tESR = 0x0000000096000007 \tEC = 0x25: DABT (current EL), IL = 32 bits \tSET = 0, FnV = 0 \tEA = 0, S1PTW = 0 \tFSC = 0x07: level 3 translation fault \tData abort info: \tISV = 0, ISS = 0x00000007, ISS2 = 0x00000000 \tCM = 0, WnR = 0, TnD = 0, TagAccess = 0 \tGCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 \tuser pgtable: 4k pages, 39-bit VAs, pgdp=00000002175aa000 \t[0000000000000058] pgd=08000002175ab003, p4d=08000002175ab003, pud=08000002175ab003, pmd=08000002175be003, pte=0000000000000000 \tpstate: 834000c5 (Nzcv daIF +PAN -UAO +TCO +DIT -SSBS BTYPE=--) \tpc : __task_pid_nr_ns+0x74/0xd0 \tlr : __task_pid_nr_ns+0x24/0xd0 \tsp : ffffffc08001bd10 \tx29: ffffffc08001bd10 x28: ffffffd4422b2000 x27: 0000000000000001 \tx26: ffffffd442821168 x25: ffffffd442821000 x24: 00000f89492eab31 \tx23: 00000000000000c0 x22: ffffff806f5693c0 x21: ffffff806f5693c0 \tx20: 0000000000000001 x19: 0000000000000000 x18: 0000000000000000 \tx17: 00000000529c6ef0 x16: 00000000529c6ef0 x15: 00000000023a1adc \tx14: 0000000000000003 x13: 00000000007ef6d8 x12: 001167c391c78800 \tx11: 00ffffffffffffff x10: 0000000000000000 x9 : 0000000000000001 \tx8 : ffffff80816fa3c0 x7 : 0000000000000000 x6 : 49534d702d535449 \tx5 : ffffffc080c4c2c0 x4 : ffffffd43ee128c8 x3 : ffffffd43ee124dc \tx2 : 0000000000000000 x1 : 0000000000000001 x0 : ffffff806f5693c0 \tCall trace: \t__task_pid_nr_ns+0x74/0xd0 \t... \t__handle_irq_event_percpu+0xd4/0x284 \thandle_irq_event+0x48/0xb0 \thandle_fasteoi_irq+0x160/0x2d8 \tgeneric_handle_domain_irq+0x44/0x60 \tgic_handle_irq+0x4c/0x114 \tcall_on_irq_stack+0x3c/0x74 \tdo_interrupt_handler+0x4c/0x84 \tel1_interrupt+0x34/0x58 \tel1h_64_irq_handler+0x18/0x24 \tel1h_64_irq+0x68/0x6c \taccount_kernel_stack+0x60/0x144 \texit_task_stack_account+0x1c/0x80 \tdo_exit+0x7e4/0xaf8 \t... \tget_signal+0x7bc/0x8d8 \tdo_notify_resume+0x128/0x828 \tel0_svc+0x6c/0x70 \tel0t_64_sync_handler+0x68/0xbc \tel0t_64_sync+0x1a8/0x1ac \tCode: 35fffe54 911a02a8 f9400108 b4000128 (b9405a69) \t---[ end trace 0000000000000000 ]--- \tKernel panic - not syncing: Oops: Fatal exception in interrupt","modified":"2026-09-01T16:06:17.110589189Z","published":"2025-11-12T22:15:44.480Z","upstream":["CVE-2025-40178"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-40178"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.158-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.148-1","6.1.153-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40178.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.57-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40178.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.6-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.2-1~exp1","6.17.5-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40178.json"}}],"schema_version":"1.9.0"}