cbcvebase.
CVE-2025-40078
published 2025-10-28

CVE-2025-40078: In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Syzkaller found a kernel warning on the…

PriorityP422high7.8
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Syzkaller found a kernel warning on the following sock_addr program: 0: r0 = 0 1: r2 = *(u32 *)(r1 +60) 2: exit which triggers: verifier bug: error during ctx access conversion (0) This is happening because offset 60 in bpf_sock_addr corresponds to an implicit padding of 4 bytes, right after msg_src_ip4. Access to this padding isn't rejected in sock_addr_is_valid_access and it thus later fails to convert the access. This patch fixes it by explicitly checking the various fields of bpf_sock_addr in sock_addr_is_valid_access. I checked the other ctx structures and is_valid_access functions and didn't find any other similar cases. Other cases of (properly handled) padding are covered in new tests in a subsequent patch.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < de44cdc50d2dce8718cb57deddf9cf1be9a7759fde44cdc50d2dce8718cb57deddf9cf1be9a7759f
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < 76e04bbb4296fb6eac084dbfc27e02ccc744db3e76e04bbb4296fb6eac084dbfc27e02ccc744db3e
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < 6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < 4f00858cd9bbbdf67159e28b85a8ca9e77c836224f00858cd9bbbdf67159e28b85a8ca9e77c83622
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < cdeafacb4f9ff261a96baef519e29480fd7b1019cdeafacb4f9ff261a96baef519e29480fd7b1019
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < fe9d33f0470350558cb08cecb54cf2267b3a45d2fe9d33f0470350558cb08cecb54cf2267b3a45d2
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69
linuxlinux>= 1cedee13d25ab118d325f95588c1a084e9317229 < 6fabca2fc94d33cdf7ec102058983b086293395f6fabca2fc94d33cdf7ec102058983b086293395f
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.18.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1955.15.195
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.