CVE-2025-40204: Linux

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

Affected products

  • Linux Linux: from 2.6.12, before 5.4.301 (fixed in 5.4.301); from 5.5, before 5.10.246 (fixed in 5.10.246); from 5.11, before 5.15.195 (fixed in 5.15.195); from 5.16, before 6.1.157 (fixed in 6.1.157); from 6.2, before 6.6.113 (fixed in 6.6.113); from 6.7, before 6.12.54 (fixed in 6.12.54); …

Published 2025-11-12. Last modified 2026-07-30.