CVE-2025-40075 (GCVE-0-2025-40075)
Vulnerability from cvelistv5
Published
2025-10-28 11:48
Modified
2026-08-05 12:07
Summary
In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three dst_dev() with a lockdep enabled helper.
Impacted products
Vendor Product Version
Linux Linux Version: 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36
Version: 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36
Version: 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/tcp_metrics.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4b89397807eb04986427c4786d065e9442834ad4",
              "status": "affected",
              "version": "4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36",
              "versionType": "git"
            },
            {
              "lessThan": "07613a95326ebad2d1b88d883cd72546025a4f3e",
              "status": "affected",
              "version": "4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36",
              "versionType": "git"
            },
            {
              "lessThan": "50c127a69cd6285300931853b352a1918cfa180f",
              "status": "affected",
              "version": "4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/tcp_metrics.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "lessThan": "4.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.63",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.17.*",
              "status": "unaffected",
              "version": "6.17.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.63",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17.3",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: use dst_dev_net_rcu()\n\nReplace three dst_dev() with a lockdep enabled helper."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The three fixed call sites sit in the core TCP metrics cache, reached from `tcp_conn_request()` on an inbound SYN, from `tcp_finish_connect()`, from the TIME-WAIT/LAST-ACK teardown path, and from TCP Fast Open \u2014 all driven purely by packets from a remote peer. No local access is needed to reach the vulnerable code.\nAC:H - The stale `dst-\u003edev` window only exists while `dst_dev_put()` is concurrently swapping the device to the blackhole netdev during a route removal or NETDEV_DOWN/UNREGISTER event, which a remote attacker cannot induce or time. The attacker controls only the TCP-connection side of the race.\nPR:N - `tcp_peer_is_proven()` is invoked from `tcp_conn_request()` while processing an unauthenticated SYN, before any application-level credentials exist, and the other paths only require establishing or closing a normal TCP connection. No kernel privilege check or capability gate exists anywhere along the path.\nUI:N - The code runs entirely from softirq/socket context on packet receive and connection teardown; no local user or administrator action is required to trigger it.\nS:U - The unprotected dereference and its consequences are confined to the kernel\u0027s own memory and the network stack \u2014 the same security authority. There is no VM, IOMMU, or sandbox boundary crossed.\nC:H - A use-after-free read of a released `struct net_device` yields a `struct net` pointer taken from reclaimed memory, which is then used to compute hashes and index the per-namespace metrics cache; attacker-groomed heap contents can be interpreted as kernel structures, enabling disclosure of kernel memory.\nI:H - The bogus `struct net` derived from the freed device is stored into `tm-\u003etcpm_net` and drives `tcpm_new()`/`tcpm_suck_dst()` writes, so freed or attacker-controlled memory is treated as a live namespace object \u2014 a UAF of this class is leverageable for controlled kernel writes and control-flow hijack.\nA:H - Dereferencing a freed `net_device` through `dev_net_rcu()` and then using the resulting garbage `struct net` pointer for `net_hash_mix()` and cache lookups leads to an oops or panic, taking down the whole system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:07:34.647Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4b89397807eb04986427c4786d065e9442834ad4"
        },
        {
          "url": "https://git.kernel.org/stable/c/07613a95326ebad2d1b88d883cd72546025a4f3e"
        },
        {
          "url": "https://git.kernel.org/stable/c/50c127a69cd6285300931853b352a1918cfa180f"
        }
      ],
      "title": "tcp_metrics: use dst_dev_net_rcu()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-40075",
    "datePublished": "2025-10-28T11:48:41.791Z",
    "dateReserved": "2025-04-16T07:20:57.160Z",
    "dateUpdated": "2026-08-05T12:07:34.647Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…