cbcvebase.
CVE-2025-40176
published 2025-11-12

CVE-2025-40176: In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryption calls…

PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.42%
34.6th percentile
In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryption calls tls_strp_msg_hold to create a clone of the input skb to hold references to the memory it uses. If we fail to allocate that clone, proceeding with async decryption can lead to various issues (UAF on the skb, writing into userspace memory after the recv() call has returned). In this case, wait for all pending decryption requests.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 84c61fe1a75b4255df1e1e7c054c9e6d048da417 < 9f83fd0c179e0f458e824e417f9d5ad53443f6859f83fd0c179e0f458e824e417f9d5ad53443f685
linuxlinux>= 84c61fe1a75b4255df1e1e7c054c9e6d048da417 < c61d4368197d65c4809d9271f3b85325a600586ac61d4368197d65c4809d9271f3b85325a600586a
linuxlinux>= 84c61fe1a75b4255df1e1e7c054c9e6d048da417 < 39dec4ea3daf77f684308576baf483b55ca7f16039dec4ea3daf77f684308576baf483b55ca7f160
linuxlinux>= 84c61fe1a75b4255df1e1e7c054c9e6d048da417 < 4fc109d0ab196bd943b7451276690fb6bb48c2e04fc109d0ab196bd943b7451276690fb6bb48c2e0
linuxlinux>= 84c61fe1a75b4255df1e1e7c054c9e6d048da417 < b8a6ff84abbcbbc445463de58704686011edc8e1b8a6ff84abbcbbc445463de58704686011edc8e1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.0.0 < 6.1.1586.1.158
linuxlinux_kernel>= 6.13.0 < 6.17.56.17.5
linuxlinux_kernel>= 6.2.0 < 6.6.1146.6.114
linuxlinux_kernel>= 6.7.0 < 6.12.556.12.55
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_msrc8.4HIGH
vendor_ubuntu7.8HIGH
vendor_redhat7.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.