CVE-2025-40134 is a race condition in the Linux kernel device-mapper suspension path involving __dm_suspend() and concurrent table loading. During request-queue initialization, q->mq_ops can be assigned before q->tag_set. If suspension proceeds during this interval, dm_stop_queue() or dm_wait_for_completion() can encounter a NULL q->tag_set. The documented fault occurs in blk_mq_wait_quiesce_done(), reached through blk_mq_quiesce_queue(), dm_stop_queue(), and __dm_suspend(). The resulting NULL pointer dereference can crash the kernel and cause denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel device-mapper race condition can cause a NULL pointer dereference when device suspension occurs before table loading completes, potentially causing a kernel crash and denial of service. The reported CVSS v3 base score is 4.7, with local access, low privileges, and high attack complexity required. The fix checks for a valid device-mapper table before performing table-dependent suspension operations.
A Linux kernel device-mapper race condition can cause a NULL pointer dereference when device suspension overlaps with table loading, potentially crashing the kernel and causing local denial of service. The listed CVSS v3 score is 4.7, with local access, low privileges, and high attack complexity required. The fix checks for a valid device-mapper table before performing table-dependent suspension operations.
A Linux kernel device-mapper race condition that can trigger a NULL-pointer dereference and local denial of service during concurrent device suspend and table-load operations.
Linux kernel device-mapper vulnerability involving a NULL pointer dereference in __dm_suspend().
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.