CVE-2025-40149: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the only ->ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.

Affected products

  • Linux Linux Kernel: from 4.18, before 5.15.199 (fixed in 5.15.199); from 5.16, before 6.1.161 (fixed in 6.1.161); from 6.2, before 6.6.121 (fixed in 6.6.121); from 6.7, before 6.12.66 (fixed in 6.12.66); from 6.13, before 6.17.3 (fixed in 6.17.3)

Published 2025-11-12. Last modified 2026-07-30.