DEBIAN-CVE-2025-40240
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 04 Dec 2025, 16:16
Last modified:28 Apr 2026, 20:30
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Dec 2025, 16:16
Published
Vulnerability first disclosed
28 Apr 2026, 20:30
Last Modified
Vulnerability information updated
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer is missing chunk->skb pointer is dereferenced in the if-block where it's supposed to be NULL only. chunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list instead and do it just before replacing chunk->skb. We're sure that otherwise chunk->skb is non-NULL because of outer if() condition.
Affected Systems
- debian•linux
< 5.10.247-1 | < 6.1.158-1 | < 6.12.57-1 | < 6.17.6-1