CVE-2025-40278 — Linux vulnerability
49 documents7 sources
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 75.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
Fix a KMSAN kernel-infoleak detected by the syzbot .
[net?] KMSAN: kernel-infoleak in __skb_datagram_iter
In tcf_ife_dump(), the variable 'opt' was partially initialized using a
designatied initializer. While the padding bytes are reamined
uninitialized. nla_put() copies the entire structure into a
netlink message, these uninitialized bytes leaked to …
Affected Packages7 packages
▶CVEListV5linux/linuxef6980b6becb1afd9d82a4f043749a10ae81bf14 — 918e063304f945fb93be9bb70cacea07d0b730ea+8