CVE-2025-40168: Linux
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the returned value of smc_clc_prfx_match() is not used in the caller.
Affected products
- Linux Linux: from 4.11, before 6.1.187 (fixed in 6.1.187); from 6.2, before 6.6.156 (fixed in 6.6.156); from 6.7, before 6.12.108 (fixed in 6.12.108); from 6.13, before 6.17.3 (fixed in 6.17.3)
Published 2025-11-12. Last modified 2026-09-02.