CVE-2025-40149

HIGH

Linux Kernel - Use After Free

Title source: llm

Description

In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the only ->ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (6)

linux/Kernel < 5.15.199linux
linux/Kernel < 6.1.161linux
linux/Kernel < 6.6.121linux
linux/Kernel < 6.12.66linux
linux/Kernel < 6.17.3linux
linux/linux_kernel < 5.15.199

Timeline

Published Nov 12, 2025
Tracked Since Feb 18, 2026