CVE Database
/

CVE-2025-40158

Back to search

CVE-2025-40158

Published: Nov 12, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().

VendorProductVersions

Linux

Linux

affected
4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 - < 0393f85c3241c19ba8550f04a812e7d19f6b3082
affected
4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 - < 11709573cc4e48dc34c80fc7ab9ce5b159e29695

Linux

Linux

affected
4.13
unaffected
0 - < 4.13
unaffected
6.17.3 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-40158 - Security Vulnerability | QwikSec