cbcvebase.
CVE-2025-40331
published 2025-12-09

CVE-2025-40331: In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the sock lock…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the sock lock, sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump() make sure not to exceed bounds in case the address list has grown between buffer allocation (time-of-check) and write (time-of-use).

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < b106a68df0650b694b254427cd9250c04500edd3b106a68df0650b694b254427cd9250c04500edd3
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 3006959371007fc2eae4a078f823c680fa52de1a3006959371007fc2eae4a078f823c680fa52de1a
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 72e3fea68eac8d088e44c3dd954e843478e9240e72e3fea68eac8d088e44c3dd954e843478e9240e
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 584307275b2048991b2e8984962189b6cc0a9b85584307275b2048991b2e8984962189b6cc0a9b85
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < c9119f243d9c0da3c3b5f577a328de3e7ffd1b42c9119f243d9c0da3c3b5f577a328de3e7ffd1b42
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 2fe08fcaacb7eb019fa9c81db39b2214de2166772fe08fcaacb7eb019fa9c81db39b2214de216677
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 89eac1e150dbd42963e13d23828cb8c4e076319689eac1e150dbd42963e13d23828cb8c4e0763196
linuxlinux>= 8f840e47f190cbe61a96945c13e9551048d42cef < 95aef86ab231f047bb8085c70666059b58f53c0995aef86ab231f047bb8085c70666059b58f53c09
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.7.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.