CVE-2025-40037 | Linux Kernel up to 6.12.52/6.17.2 fbdev simplefb_detach_genpds use after free (Nessus ID 271881 / WID-SEC-2025-2431)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.52/6.17.2. The affected element is the function simplefb_detach_genpds of the component fbdev. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-40037. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.