CVE-2025-40158

Updated: 2026-02-09 05:35:49.599844

Description:

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.0

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.0 HIGH Needs Triage 2026-02-09 19:28:19
CentOS 8.4 ELS kernel 4.18.0 7.0 HIGH Needs Triage 2026-02-09 19:28:14
CentOS 8.5 ELS kernel 4.18.0 7.0 HIGH Needs Triage 2026-02-09 19:28:13
CentOS Stream 8 ELS kernel 4.18.0 7.0 HIGH Needs Triage 2026-02-09 19:28:21
TuxCare 9.6 ESU kernel 5.14.0 7.0 HIGH Needs Triage 2026-02-09 19:28:17