Junglewise Threat Intelligence

CVE-2025-39812: Linux Kernel uninitialized memory use in SCTP IPv6 component

CVE-2025-39812 · Severity: medium · CVSS 5.5 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's implementation of the SCTP networking protocol. This flaw could allow a local user to cause a system crash or unpredictable behavior due to the way the system handles certain network address data. This primarily impacts the availability of the affected system.

Technical details

A 'use of uninitialized resource' vulnerability (CWE-908) exists in the Linux kernel SCTP (Stream Control Transmission Protocol) implementation. The function sctp_v6_from_sk() failed to properly initialize the sin6_scope_id and sin6_flowinfo fields when creating IPv6 address structures. This leads to an uninitialized-value bug in __sctp_v6_cmp_addr during address comparison operations, such as when starting a listen socket or resolving bind address conflicts. An attacker with local access could exploit this to trigger undefined behavior or a kernel panic (Denial of Service). The issue has been resolved by explicitly clearing these fields in the affected function across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.12-rc2 to 6.16.5

Timeline

  • 2025-08-26: patched: Initial patch authored by Eric Dumazet
  • 2025-09-16: disclosed: CVE published

References

Related threats