[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-40123":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":14,"duplicates":75,"related":76,"reserved_at":9,"published_at":89,"modified_at":90,"state":91,"summary":92,"references_raw":96,"kevs":119,"epss":120,"epss_history":123,"metrics":396,"affected":397},"CVE-2025-40123","In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue.",null,[],[],[],[],[15,17,19,21,23,25,27,29,31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73],{"_key":16},"DLA-4379-1",{"_key":18},"SUSE-SU-2026:0278-1",{"_key":20},"SUSE-SU-2026:0281-1",{"_key":22},"SUSE-SU-2026:0315-1",{"_key":24},"SUSE-SU-2026:0316-1",{"_key":26},"SUSE-SU-2026:20207-1",{"_key":28},"SUSE-SU-2026:20220-1",{"_key":30},"SUSE-SU-2026:20228-1",{"_key":32},"SUSE-SU-2026:20477-1",{"_key":34},"SUSE-SU-2026:20498-1",{"_key":36},"OPENSUSE-SU-2026:20145-1",{"_key":38},"SUSE-SU-2026:20845-1",{"_key":40},"SUSE-SU-2026:20876-1",{"_key":42},"USN-8029-1",{"_key":44},"USN-8029-2",{"_key":46},"USN-8029-3",{"_key":48},"USN-8030-1",{"_key":50},"DEBIAN-CVE-2025-40123",{"_key":52},"USN-8095-1",{"_key":54},"USN-8095-2",{"_key":56},"USN-8095-3",{"_key":58},"USN-8095-4",{"_key":60},"USN-8095-5",{"_key":62},"USN-8100-1",{"_key":64},"USN-8125-1",{"_key":66},"USN-8165-1",{"_key":68},"USN-8126-1",{"_key":70},"UBUNTU-CVE-2025-40123",{"_key":72},"USN-8048-1",{"_key":74},"USN-8261-1",[],[77,78,79,80,81,82,83,84,85,86,87,88],{"_key":18},{"_key":20},{"_key":22},{"_key":24},{"_key":26},{"_key":28},{"_key":30},{"_key":32},{"_key":34},{"_key":36},{"_key":38},{"_key":40},"2025-11-12T10:23:19.589Z","2026-05-11T21:43:07.543Z","Deferred",{"cisa_kev":93,"cisa_ransomware":93,"cisa_vendor":9,"epss_severity":94,"epss_score":95,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":91},false,"low",0.00042,[97,103,107,111,115],{"url":98,"sources":99,"tags":102},"https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8",[100,101],"cve.org","nvd",[],{"url":104,"sources":105,"tags":106},"https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",[100,101],[],{"url":108,"sources":109,"tags":110},"https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",[100,101],[],{"url":112,"sources":113,"tags":114},"https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",[100,101],[],{"url":116,"sources":117,"tags":118},"https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0",[100,101],[],[],{"date":121,"score":95,"percentile":122},"2026-06-03",0.13127,[124,128,131,134,137,140,143,147,150,153,156,159,162,165,168,172,175,178,181,184,187,189,192,195,198,201,204,207,210,213,216,219,222,226,229,232,235,238,241,244,247,250,253,256,259,262,265,268,271,274,277,280,283,286,289,292,296,299,302,305,308,311,314,317,320,323,326,329,332,336,339,342,345,348,351,354,357,360,363,366,369,371,374,377,380,383,385,387,390,393],{"date":125,"score":126,"percentile":127},"2025-11-12",0.00018,0.03402,{"date":129,"score":126,"percentile":130},"2025-11-13",0.03437,{"date":132,"score":126,"percentile":133},"2025-11-14",0.0345,{"date":135,"score":126,"percentile":136},"2025-11-15",0.03479,{"date":138,"score":126,"percentile":139},"2025-11-16",0.03476,{"date":141,"score":126,"percentile":142},"2025-11-17",0.03461,{"date":144,"score":145,"percentile":146},"2025-11-18",0.00024,0.03061,{"date":148,"score":145,"percentile":149},"2025-11-19",0.03112,{"date":151,"score":145,"percentile":152},"2025-11-20",0.03176,{"date":154,"score":145,"percentile":155},"2025-11-21",0.05234,{"date":157,"score":145,"percentile":158},"2025-11-22",0.05227,{"date":160,"score":145,"percentile":161},"2025-11-23",0.05213,{"date":163,"score":145,"percentile":164},"2025-11-24",0.05195,{"date":166,"score":145,"percentile":167},"2025-11-25",0.05207,{"date":169,"score":170,"percentile":171},"2025-11-26",0.00041,0.12121,{"date":173,"score":170,"percentile":174},"2025-11-27",0.12128,{"date":176,"score":170,"percentile":177},"2025-11-28",0.12122,{"date":179,"score":170,"percentile":180},"2025-11-29",0.12074,{"date":182,"score":170,"percentile":183},"2025-11-30",0.12075,{"date":185,"score":170,"percentile":186},"2025-12-01",0.12112,{"date":188,"score":170,"percentile":177},"2025-12-02",{"date":190,"score":170,"percentile":191},"2025-12-03",0.12129,{"date":193,"score":170,"percentile":194},"2025-12-04",0.12119,{"date":196,"score":170,"percentile":197},"2025-12-05",0.12165,{"date":199,"score":170,"percentile":200},"2025-12-06",0.12178,{"date":202,"score":170,"percentile":203},"2025-12-07",0.12169,{"date":205,"score":170,"percentile":206},"2025-12-08",0.12174,{"date":208,"score":170,"percentile":209},"2025-12-09",0.12229,{"date":211,"score":170,"percentile":212},"2025-12-10",0.12296,{"date":214,"score":170,"percentile":215},"2025-12-11",0.12321,{"date":217,"score":170,"percentile":218},"2025-12-12",0.12361,{"date":220,"score":170,"percentile":221},"2025-12-13",0.12379,{"date":223,"score":224,"percentile":225},"2025-12-14",0.00045,0.13712,{"date":227,"score":224,"percentile":228},"2025-12-15",0.13677,{"date":230,"score":224,"percentile":231},"2025-12-16",0.13681,{"date":233,"score":224,"percentile":234},"2025-12-17",0.1378,{"date":236,"score":224,"percentile":237},"2025-12-18",0.13837,{"date":239,"score":224,"percentile":240},"2025-12-19",0.13882,{"date":242,"score":224,"percentile":243},"2025-12-20",0.1387,{"date":245,"score":224,"percentile":246},"2025-12-21",0.13829,{"date":248,"score":224,"percentile":249},"2025-12-22",0.13779,{"date":251,"score":224,"percentile":252},"2025-12-23",0.13776,{"date":254,"score":224,"percentile":255},"2025-12-24",0.13771,{"date":257,"score":224,"percentile":258},"2025-12-25",0.13842,{"date":260,"score":224,"percentile":261},"2025-12-26",0.13802,{"date":263,"score":224,"percentile":264},"2025-12-27",0.13804,{"date":266,"score":224,"percentile":267},"2025-12-28",0.13774,{"date":269,"score":224,"percentile":270},"2025-12-29",0.13671,{"date":272,"score":224,"percentile":273},"2025-12-30",0.1368,{"date":275,"score":224,"percentile":276},"2025-12-31",0.13744,{"date":278,"score":224,"percentile":279},"2026-01-01",0.13817,{"date":281,"score":224,"percentile":282},"2026-01-02",0.13805,{"date":284,"score":224,"percentile":285},"2026-01-03",0.13772,{"date":287,"score":224,"percentile":288},"2026-01-04",0.13695,{"date":290,"score":224,"percentile":291},"2026-01-05",0.13649,{"date":293,"score":294,"percentile":295},"2026-01-06",0.00037,0.10838,{"date":297,"score":294,"percentile":298},"2026-01-07",0.10869,{"date":300,"score":294,"percentile":301},"2026-01-08",0.10921,{"date":303,"score":294,"percentile":304},"2026-01-09",0.10948,{"date":306,"score":294,"percentile":307},"2026-01-10",0.10958,{"date":309,"score":294,"percentile":310},"2026-01-11",0.10934,{"date":312,"score":294,"percentile":313},"2026-01-12",0.1091,{"date":315,"score":294,"percentile":316},"2026-01-13",0.10886,{"date":318,"score":294,"percentile":319},"2026-01-14",0.10942,{"date":321,"score":294,"percentile":322},"2026-01-15",0.10953,{"date":324,"score":294,"percentile":325},"2026-01-16",0.10994,{"date":327,"score":294,"percentile":328},"2026-01-17",0.11005,{"date":330,"score":294,"percentile":331},"2026-01-18",0.10955,{"date":333,"score":334,"percentile":335},"2026-01-19",0.00039,0.11547,{"date":337,"score":334,"percentile":338},"2026-01-20",0.11528,{"date":340,"score":334,"percentile":341},"2026-01-21",0.11509,{"date":343,"score":334,"percentile":344},"2026-01-22",0.11495,{"date":346,"score":334,"percentile":347},"2026-01-23",0.11583,{"date":349,"score":334,"percentile":350},"2026-01-24",0.11635,{"date":352,"score":334,"percentile":353},"2026-01-25",0.11588,{"date":355,"score":334,"percentile":356},"2026-01-26",0.11527,{"date":358,"score":334,"percentile":359},"2026-01-27",0.11513,{"date":361,"score":334,"percentile":362},"2026-01-28",0.11505,{"date":364,"score":334,"percentile":365},"2026-01-29",0.11483,{"date":367,"score":334,"percentile":368},"2026-01-30",0.11512,{"date":370,"score":334,"percentile":338},"2026-01-31",{"date":372,"score":334,"percentile":373},"2026-02-01",0.11534,{"date":375,"score":334,"percentile":376},"2026-02-02",0.11492,{"date":378,"score":334,"percentile":379},"2026-02-03",0.11459,{"date":381,"score":334,"percentile":382},"2026-02-04",0.11456,{"date":384,"score":334,"percentile":368},"2026-02-05",{"date":386,"score":334,"percentile":359},"2026-02-06",{"date":388,"score":334,"percentile":389},"2026-02-07",0.11532,{"date":391,"score":334,"percentile":392},"2026-02-08",0.11518,{"date":394,"score":334,"percentile":395},"2026-02-09",0.11487,[],[398],{"ecosystem":9,"name":399,"vendor":400,"product":400,"cpe_part":401,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":402},"Linux","linux","a",[403,410,413,416,419,422],{"version":404,"is_range":405,"range_type":100,"version_start":406,"version_start_type":407,"version_end":408,"version_end_type":409,"fixed_in":9},">= 5e43f899b03a3492ce5fc44e8900becb04dae9c0, \u003C a99de19128aec0913f3d529f529fbbff5edfaff8",true,"5e43f899b03a3492ce5fc44e8900becb04dae9c0","including","a99de19128aec0913f3d529f529fbbff5edfaff8","excluding",{"version":411,"is_range":405,"range_type":100,"version_start":406,"version_start_type":407,"version_end":412,"version_end_type":409,"fixed_in":9},">= 5e43f899b03a3492ce5fc44e8900becb04dae9c0, \u003C 08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32","08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",{"version":414,"is_range":405,"range_type":100,"version_start":406,"version_start_type":407,"version_end":415,"version_end_type":409,"fixed_in":9},">= 5e43f899b03a3492ce5fc44e8900becb04dae9c0, \u003C f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a","f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",{"version":417,"is_range":405,"range_type":100,"version_start":406,"version_start_type":407,"version_end":418,"version_end_type":409,"fixed_in":9},">= 5e43f899b03a3492ce5fc44e8900becb04dae9c0, \u003C c1ad19b5d8e23123503dcaf2d4342e1b90b923ad","c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",{"version":420,"is_range":405,"range_type":100,"version_start":406,"version_start_type":407,"version_end":421,"version_end_type":409,"fixed_in":9},">= 5e43f899b03a3492ce5fc44e8900becb04dae9c0, \u003C 4540aed51b12bc13364149bf95f6ecef013197c0","4540aed51b12bc13364149bf95f6ecef013197c0",{"version":423,"is_range":93,"range_type":100,"version_start":423,"version_start_type":407,"version_end":423,"version_end_type":407,"fixed_in":9},"4.17"]