CVE-2025-40055

Updated on 28 Oct 2025

Severity

Awaiting Analysis

Details

CVSS score
8.6

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix double free in user_cluster_connect()

user_cluster_disconnect() frees “conn->cc_private” which is “lc” but then the error handling frees “lc” a second time. Set “lc” to NULL on this path to avoid a double free.

Details

Affected packages:
kernel @ 3.10.0 (+2 more)

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix double free in user_cluster_connect()

user_cluster_disconnect() frees “conn->cc_private” which is “lc” but then the error handling frees “lc” a second time. Set “lc” to NULL on this path to avoid a double free.

Fixes