CVE-2025-40074

Source
https://cve.org/CVERecord?id=CVE-2025-40074
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40074.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-40074
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
ECHO (1)
OESA (3)
openSUSE (3)
ROOT (5)
SUSE (14)
UBUNTU (1)
Related
Published
2025-10-28T11:48:41Z
Modified
2026-09-16T03:30:50Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ipv4: start using dst_dev_rcu()
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv4: start using dst_dev_rcu()

Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.

Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40074.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36
Fixed
e150f273cd8ed34ebc6d03758aad95c12fc58337
Fixed
684efb2c86c887685f9aa65e1a21b3df6c1f822d
Fixed
923e0734c386984d45de508528a7a7ad91d791cc
Fixed
6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40074.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.106
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40074.json"