
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40033 is a vulnerability discovered in the Linux kernel affecting the remoteproc PRU subsystem. The vulnerability was disclosed on October 28, 2025, and involves a potential NULL pointer dereference in the prurprocset_ctable() function. The issue specifically affects the Linux kernel's PRU (Programmable Real-Time Unit) remote processor framework (NVD).
The vulnerability stems from a coding error where prurprocsetctable() accessed rproc->priv before performing the ISERRORNULL check, which could lead to a null pointer dereference. The fix involves restructuring the code to ensure the pru assignment occurs after proper validation, preventing any potential NULL pointer dereferencing (NVD).
The vulnerability affects various Linux distributions and kernel versions. According to Ubuntu's security advisory, multiple kernel versions are affected, including linux-hwe-6.8, linux-hwe-6.14, linux-azure, and several other kernel variants (Ubuntu).
The issue has been resolved in the Linux kernel through a patch that corrects the order of operations in the prurprocset_ctable() function. The fix ensures proper validation before accessing the pointer, preventing the potential NULL pointer dereference (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."