CVE Database
/

CVE-2025-40240

Back to search

CVE-2025-40240

Published: Dec 4, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer is missing chunk->skb pointer is dereferenced in the if-block where it's supposed to be NULL only. chunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list instead and do it just before replacing chunk->skb. We're sure that otherwise chunk->skb is non-NULL because of outer if() condition.

VendorProductVersions

Linux

Linux

affected
90017accff61ae89283ad9a51f9ac46ca01633fb - < 61cda2777b07d27459f5cac5a047c3edf9c8a1a9
affected
90017accff61ae89283ad9a51f9ac46ca01633fb - < 08165c296597075763130919f2aae59b5822f016
affected
90017accff61ae89283ad9a51f9ac46ca01633fb - < 03e80a4b04ef1fb2c61dd63216ab8d3a5dcb196f
affected
90017accff61ae89283ad9a51f9ac46ca01633fb - < 4f6da435fb5d8a21cbf8cae5ca5a2ba0e1012b71
affected
90017accff61ae89283ad9a51f9ac46ca01633fb - < cb9055ba30306ede4ad920002233d0659982f1cb

+3 more versions

Linux

Linux

affected
4.8
unaffected
0 - < 4.8
unaffected
5.4.301 - <= 5.4.*
unaffected
5.10.246 - <= 5.10.*
unaffected
5.15.196 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now