CVE-2025-40170

Advisory lineage Upstream: 0 Downstream: 25
Deferred
Published: 12 Nov 2025, 10:46
Last modified:11 May 2026, 21:44

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Nov 2025, 10:46
Published
Vulnerability first disclosed
11 May 2026, 21:44
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size(). Also use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(), and ip_dst_mtu_maybe_forward(). ip4_dst_hoplimit() can use dst_dev_net_rcu().

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Affected Systems

  • linuxlinux

    ≥ 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36, < 5d1be493d1110c9e720b4c51a6e587bb2fb4ac12 | ≥ 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36, < a805729c0091073d8f0415cfa96c7acd1bc17a48 | ≥ 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36, < 99a2ace61b211b0be861b07fbaa062fca4b58879 | 4.13

References (3)