CVE Database
/

CVE-2025-40074

Back to search

CVE-2025-40074

Published: Oct 28, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().

VendorProductVersions

Linux

Linux

affected
4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 - < 923e0734c386984d45de508528a7a7ad91d791cc
affected
4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 - < 6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8

Linux

Linux

affected
4.13
unaffected
0 - < 4.13
unaffected
6.17.3 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now