CVE-2025-40074: Linux
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().
Affected products
- Linux Linux: from 4.13, before 6.1.189 (fixed in 6.1.189); from 6.2, before 6.6.157 (fixed in 6.6.157); from 6.7, before 6.12.106 (fixed in 6.12.106); from 6.13, before 6.17.3 (fixed in 6.17.3)
Published 2025-10-28. Last modified 2026-10-03.