cbcvebase.
CVE-2025-40149
published 2025-11-12

CVE-2025-40149: In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock()…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the only ->ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < 2b1bef126bbb8d0da51491357559126d567c1dee2b1bef126bbb8d0da51491357559126d567c1dee
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < e37ca0092ddace60833790b4ad7a390408fb1be9e37ca0092ddace60833790b4ad7a390408fb1be9
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < 13159c7125636371543a82cb7bbae00ab36730cc13159c7125636371543a82cb7bbae00ab36730cc
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < f09cd209359a23f88d4f3fa3d2379d057027e53cf09cd209359a23f88d4f3fa3d2379d057027e53c
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < feb474ddbf26b51f462ae2e60a12013bdcfc5407feb474ddbf26b51f462ae2e60a12013bdcfc5407
linuxlinux>= e8f69799810c32dd40c6724d829eccc70baad07f < c65f27b9c3be2269918e1cbad6d8884741f835c5c65f27b9c3be2269918e1cbad6d8884741f835c5
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.18 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1616.1.161
linuxlinux_kernel>= 6.13 < 6.17.36.17.3
linuxlinux_kernel>= 6.2 < 6.6.1216.6.121
linuxlinux_kernel>= 6.7 < 6.12.666.12.66
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.