CVE-2025-40256 — Incomplete Cleanup in Linux
Severity
7.1HIGH
No vectorEPSS
0.0%
top 85.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were never added
In commit b441cf3f8c4b ("xfrm: delete x->tunnel as we delete x"), I
missed the case where state creation fails between full
initialization (->init_state has been called) and being inserted on
the lists.
In this situation, ->init_state has been called, so for IPcomp
tunnels, the fallback tunnel has been created and added onto the
lists, b…
Affected Packages5 packages
▶CVEListV5linux/linux1b28a7fae0128fa140a7dccd995182ff6cd1c67b — 57b72d74d4651dc19d046308a8304eb9abfe66ac+7
🔴Vulnerability Details
8📋Vendor Advisories
6Red Hat▶
kernel: xfrm: also call xfrm_state_delete_tunnel at destroy time for states that were never added↗2025-12-04