
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40107 is a vulnerability discovered in the Linux kernel, specifically affecting the hi311x CAN (Controller Area Network) driver. The vulnerability was identified and disclosed in November 2025, involving a null pointer dereference issue that occurs during the system resume process (NVD).
The vulnerability is characterized as a null pointer dereference in the hi311x CAN driver component of the Linux kernel. This issue specifically manifests during the system resume operation (Rapid7).
The vulnerability has been included in a larger security update addressing multiple issues that could potentially lead to privilege escalation, denial of service, or information leaks in the Linux kernel (Debian Security).
The vulnerability has been fixed in Linux kernel version 6.1.158-1 for the Debian oldstable distribution (bookworm). Users are recommended to upgrade their Linux packages to the latest version to address this security issue (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."