In the Linux kernel, the following vulnerability has been resolved:
sctp: Fix MAC comparison to be constant-time
To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dd91c79e4f58fbe2898dac84858033700e0e99fb",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-028daf04",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b93fa8dc521d00d2d44bf034fb90e0d79b036617",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-1b59ee42",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-31fc70fc",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8019b3699289fce3f10b63f98601db97b8d105b0",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-3f748006",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b32ff285ff6f6f1ac1d9495787ccce8837d6405",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-5de81076",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b93fa8dc521d00d2d44bf034fb90e0d79b036617",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-77811ad2",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9c05d44ec24126fc283835b68f82dba3ae985209",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-961e4008",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-9a0a461d",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b32ff285ff6f6f1ac1d9495787ccce8837d6405",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-a1312879",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e8b8c326c2a6de4d837b1bb034ea704f4690d77",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-a536058c",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ed3044b9c810c5c24eb2830053fbfe5fd134c5d4",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-ab7b53e2",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9c05d44ec24126fc283835b68f82dba3ae985209",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-b159bced",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8019b3699289fce3f10b63f98601db97b8d105b0",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-c44fce93",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ed3044b9c810c5c24eb2830053fbfe5fd134c5d4",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-cf1ba177",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e8b8c326c2a6de4d837b1bb034ea704f4690d77",
"target": {
"file": "net/sctp/sm_make_chunk.c"
},
"id": "CVE-2025-40204-d898c873",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262533055190447765960830987290134489396",
"309571012558889850183943575464173786670",
"246076284983661137186365782509175845486",
"324569517532691632102225108202910643309",
"39441339105497010297357891884999531293"
]
},
"deprecated": false,
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dd91c79e4f58fbe2898dac84858033700e0e99fb",
"target": {
"file": "net/sctp/sm_statefuns.c"
},
"id": "CVE-2025-40204-ebf6219a",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224104983264987247565514201401778402354",
"92038081423005139182349399937500816322",
"185396362759271660761139423092959408445",
"276171839722584544783923233116638603405",
"24228092674444426771404497039572027095"
]
},
"deprecated": false,
"signature_version": "v1"
}
]