Answer in brief
CVE-2025-40164 records a Medium severity (CVSS 5.5) vulnerability in usbnet: Fix using smp_processor_id() in preemptible code warnings. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-40164 records a Medium severity (CVSS 5.5) vulnerability in usbnet: Fix using smp_processor_id() in preemptible code warnings. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <6635e52bc4165793aefd686962d912d73d323afe || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <65d04291adf7c59338f87aab9c6fe0bfa9993e64 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <f45fffae5e2549bd0a4670cc52a15ad54c9f121e || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <17fbad93879e87a334062882b45fa727ba1b3dd7 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <d1944bab8e0c1511f0cbf364aa06547735bb0ddb || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <0134c7bff14bd50314a4f92b182850ddfc38e255 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <327cd4b68b4398b6c24f10eb2b2533ffbfc10185 | 6635e52bc4165793aefd686962d912d73d323afe, 65d04291adf7c59338f87aab9c6fe0bfa9993e64, f45fffae5e2549bd0a4670cc52a15ad54c9f121e, 17fbad93879e87a334062882b45fa727ba1b3dd7, d1944bab8e0c1511f0cbf364aa06547735bb0ddb, 0134c7bff14bd50314a4f92b182850ddfc38e255, 327cd4b68b4398b6c24f10eb2b2533ffbfc10185 |
| Linux/Linuxgeneric | 4.7 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot reported the following warning: BUG: using smp_processor_id() in preemptible [00000000] code: dhcpcd/2879 caller is usbnet_skb_return+0x74/0x490 drivers/net/usb/usbnet.c:331 CPU: 1 UID: 0 PID: 2879 Comm: dhcpcd Not tainted 6.15.0-rc4-syzkaller-00098-g615dca38c2ea #0 PREEMPT(voluntary) Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 check_preemption_disabled+0xd0/0xe0 lib/smp_processor_id.c:49 usbnet_skb_return+0x74/0x490 drivers/net/usb/usbnet.c:331 usbnet_resume_rx+0x4b/0x170 drivers/net/usb/usbnet.c:708 usbnet_change_mtu+0x1be/0x220 drivers/net/usb/usbnet.c:417 __dev_set_mtu net/core/dev.c:9443 [inline] netif_set_mtu_ext+0x369/0x5c0 net/core/dev.c:9496 netif_set_mtu+0xb0/0x160 net/core/dev.c:9520 dev_set_mtu+0xae/0x170 net/core/dev_api.c:247 dev_ifsioc+0xa31/0x18d0 net/core/dev_ioctl.c:572 dev_ioctl+0x223/0x10e0 net/core/dev_ioctl.c:821 sock_do_ioctl+0x19d/0x280 net/socket.c:1204 sock_ioctl+0x42f/0x6a0 net/socket.c:1311 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:906 [inline] __se_sys_ioctl fs/ioctl.c:892 [inline] __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0x260 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f For historical and portability reasons, the netif_rx() is usually run in the softirq or interrupt context, this commit therefore add local_bh_disable/enable() protection in the usbnet_resume_rx().
Quoted source text, attributed separately from HOL analysis.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <6635e52bc4165793aefd686962d912d73d323afe || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <65d04291adf7c59338f87aab9c6fe0bfa9993e64 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <f45fffae5e2549bd0a4670cc52a15ad54c9f121e || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <17fbad93879e87a334062882b45fa727ba1b3dd7 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <d1944bab8e0c1511f0cbf364aa06547735bb0ddb || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <0134c7bff14bd50314a4f92b182850ddfc38e255 || >=43daa96b166c3cf5ff30dfac0c5efa2620e4beab <327cd4b68b4398b6c24f10eb2b2533ffbfc10185 | 6635e52bc4165793aefd686962d912d73d323afe, 65d04291adf7c59338f87aab9c6fe0bfa9993e64, f45fffae5e2549bd0a4670cc52a15ad54c9f121e, 17fbad93879e87a334062882b45fa727ba1b3dd7, d1944bab8e0c1511f0cbf364aa06547735bb0ddb, 0134c7bff14bd50314a4f92b182850ddfc38e255, 327cd4b68b4398b6c24f10eb2b2533ffbfc10185 |
| Linux/Linuxgeneric | 4.7 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot reported the following warning: BUG: using smp_processor_id() in preemptible [00000000] code: dhcpcd/2879 caller is usbnet_skb_return+0x74/0x490 drivers/net/usb/usbnet.c:331 CPU: 1 UID: 0 PID: 2879 Comm: dhcpcd Not tainted 6.15.0-rc4-syzkaller-00098-g615dca38c2ea #0 PREEMPT(voluntary) Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 check_preemption_disabled+0xd0/0xe0 lib/smp_processor_id.c:49 usbnet_skb_return+0x74/0x490 drivers/net/usb/usbnet.c:331 usbnet_resume_rx+0x4b/0x170 drivers/net/usb/usbnet.c:708 usbnet_change_mtu+0x1be/0x220 drivers/net/usb/usbnet.c:417 __dev_set_mtu net/core/dev.c:9443 [inline] netif_set_mtu_ext+0x369/0x5c0 net/core/dev.c:9496 netif_set_mtu+0xb0/0x160 net/core/dev.c:9520 dev_set_mtu+0xae/0x170 net/core/dev_api.c:247 dev_ifsioc+0xa31/0x18d0 net/core/dev_ioctl.c:572 dev_ioctl+0x223/0x10e0 net/core/dev_ioctl.c:821 sock_do_ioctl+0x19d/0x280 net/socket.c:1204 sock_ioctl+0x42f/0x6a0 net/socket.c:1311 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:906 [inline] __se_sys_ioctl fs/ioctl.c:892 [inline] __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0x260 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f For historical and portability reasons, the netif_rx() is usually run in the softirq or interrupt context, this commit therefore add local_bh_disable/enable() protection in the usbnet_resume_rx().
Quoted source text, attributed separately from HOL analysis.