CVE-2025-40109: crypto: rng - Ensure set_ent is always present
Published Nov 9, 2025
·Updated
crypto: rng - Ensure setent is always present
Affected Software
2 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.104.2-4
Event History
Nov 9, 2025
CVE Published
via MITRE·04:35 AM
Data Sourced
via MITRE·04:35 AM
Description
Data Sourced
via NVD·05:15 AM
Description
Nov 10, 2025
Data Sourced
via Microsoft·01:03 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:03 AM
Affected Software
Updated
via Microsoft·01:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-40109?
CVE-2025-40109 is classified as a medium severity vulnerability in the Linux kernel related to the cryptographic random number generator.
2
How do I fix CVE-2025-40109?
To fix CVE-2025-40109, update to the latest version of the Linux kernel that includes the patch addressing this vulnerability.
3
What is the impact of CVE-2025-40109?
The impact of CVE-2025-40109 could lead to inadequate random number generation, potentially compromising cryptographic processes.
4
Which versions of the Linux kernel are affected by CVE-2025-40109?
CVE-2025-40109 affects specific versions of the Linux kernel that do not implement the required changes to the random number generator.
5
Is CVE-2025-40109 publicly disclosed?
Yes, CVE-2025-40109 has been publicly disclosed and information about it is available in various security advisories.