CVE-2025-40332 Affecting kernel-uek-modules-usb package, versions <0:6.12.0-107.59.3.2.el10uek


Severity

Recommended
high

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.03% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE10-KERNELUEKMODULESUSB-14948829
  • published15 Jan 2026
  • disclosed9 Dec 2025

Introduced: 9 Dec 2025

CVE-2025-40332  (opens in a new tab)

How to fix?

Upgrade Oracle:10 kernel-uek-modules-usb to version 0:6.12.0-107.59.3.2.el10uek or higher.
This issue was patched in ELSA-2026-50006.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-uek-modules-usb package and not the kernel-uek-modules-usb package as distributed by Oracle. See How to fix? for Oracle:10 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix mmap write lock not release

If mmap write lock is taken while draining retry fault, mmap write lock is not released because svm_range_restore_pages calls mmap_read_unlock then returns. This causes deadlock and system hangs later because mmap read or write lock cannot be taken.

Downgrade mmap write lock to read lock if draining retry fault fix this bug.

CVSS Base Scores

version 3.1