CVE-2025-40135: Linux

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.

Affected products

  • Linux Linux: from 4.13, before 6.1.167 (fixed in 6.1.167); from 6.2, before 6.6.130 (fixed in 6.6.130); from 6.7, before 6.12.78 (fixed in 6.12.78); from 6.13, before 6.17.3 (fixed in 6.17.3)
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6; from V3.1.5
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp: from V3.1.6; from V3.1.5
  • Siemens Siplus s7-1500 CPU 1518-4 Pn/dp Mfp: from V3.1.6; from V3.1.5

Published 2025-11-12. Last modified 2026-07-30.