cbcvebase.
CVE-2025-40281
published 2025-12-06

CVE-2025-40281: In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a…

PriorityP423high7.8
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < 0e0413e3315199b23ff4aec295e256034cd0a6e40e0413e3315199b23ff4aec295e256034cd0a6e4
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < 834e65be429c0fa4f9bb5945064bd57f18ed2187834e65be429c0fa4f9bb5945064bd57f18ed2187
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < abb086b9a95d0ed3b757ee59964ba3c4e4b2fc1aabb086b9a95d0ed3b757ee59964ba3c4e4b2fc1a
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < d0d858652834dcf531342c82a0428170aa7c2675d0d858652834dcf531342c82a0428170aa7c2675
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < ed71f801249d2350c77a73dca2c03918a15a62feed71f801249d2350c77a73dca2c03918a15a62fe
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < 1cfa4eac275cc4875755c1303d48a4ddfe507ca81cfa4eac275cc4875755c1303d48a4ddfe507ca8
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < aaba523dd7b6106526c24b1fd9b5fc35e5aaa88daaba523dd7b6106526c24b1fd9b5fc35e5aaa88d
linuxlinux>= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b < 1534ff77757e44bcc4b98d0196bc5c0052fce5fa1534ff77757e44bcc4b98d0196bc5c0052fce5fa
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.9-16.17.9-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.16.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.96.17.9
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.596.12.59

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.