Junglewise Threat Intelligence

CVE-2025-40075: Linux Kernel race condition in tcp_metrics

CVE-2025-40075 · Severity: high · CVSS 8.1 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking component that handles TCP connection metrics. This component is responsible for optimizing network performance by remembering characteristics of previous connections. If exploited, this flaw could lead to system instability or unauthorized access to sensitive network data, potentially impacting the reliability and security of the server.

Technical details

A vulnerability exists in net/ipv4/tcp_metrics.c within the Linux kernel due to improper synchronization when accessing network namespace information. The code previously used dst_dev() within dev_net_rcu() calls in tcpm_new, __tcp_get_metrics_req, and tcp_get_metrics functions, which lacked proper RCU protection or lockdep validation. An attacker could potentially exploit this race condition or improper pointer dereference to cause a kernel panic or leak information. The fix replaces these calls with the dst_dev_net_rcu() helper to ensure safe RCU-protected access to the network namespace associated with a destination entry.

Affected products

  • Linux Linux Kernel 4.13 to 6.17.3

Timeline

  • 2025-08-28: patched: Initial fix developed by Eric Dumazet
  • 2025-10-28: disclosed: CVE published

References

Related threats