CVE-2025-40279 — Use of Uninitialized Resource in Linux
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 75.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
net: sched: act_connmark: initialize struct tc_ife to fix kernel leak
In tcf_connmark_dump(), the variable 'opt' was partially initialized using a
designatied initializer. While the padding bytes are reamined
uninitialized. nla_put() copies the entire structure into a
netlink message, these uninitialized bytes leaked to userspace.
Initialize the structure with memset before assigning its fields
to ensure all members and paddi…
Affected Packages7 packages
▶CVEListV5linux/linux22a5dc0e5e3e8fef804230cd73ed7b0afd4c7bae — 218b67c8c8246d47a2a7910eae80abe4861fe2b7+6