cbcvebase.
CVE-2025-40133
published 2025-11-12

CVE-2025-40133: In the Linux kernel, the following vulnerability has been resolved: mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable(). mptcp_active_enable()…

PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.47%
38.1th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable(). mptcp_active_enable() is called from subflow_finish_connect(), which is icsk->icsk_af_ops->sk_rx_dst_set() and it's not always under RCU. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu().

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 27069e7cb3d1cea9377069266acf19b9cc5ad0ae < ad16235c9d3ef7ec17c109ff39b7504f49d17072ad16235c9d3ef7ec17c109ff39b7504f49d17072
linuxlinux>= 27069e7cb3d1cea9377069266acf19b9cc5ad0ae < cc976ec9e38bb79409de3261ba1dbb6868e2a53ecc976ec9e38bb79409de3261ba1dbb6868e2a53e
linuxlinux>= 27069e7cb3d1cea9377069266acf19b9cc5ad0ae < 893c49a78d9f85e4b8081b908fb7c407d018106a893c49a78d9f85e4b8081b908fb7c407d018106a
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.12.0 < 6.12.556.12.55
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.189.1-1_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.