Junglewise Threat Intelligence

CVE-2025-40129: Linux Kernel null pointer dereference in SUNRPC checksum handling

CVE-2025-40129 · Severity: high · CVSS 7.5 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SUNRPC implementation can allow a remote attacker to crash the system. SUNRPC is a core component used for network file sharing and remote procedure calls. By sending a specially crafted network packet with a zero-length security checksum, an attacker can trigger a system failure, leading to a denial of service.

Technical details

A null pointer dereference (NPD) exists in the SUNRPC subsystem of the Linux kernel within the svcauth_gss_verify_header() function. When xdr_stream_decode_opaque_auth() encounters a zero-length checksum, it sets the checksum data pointer to NULL. Subsequent access to this pointer in gss_krb5_verify_mic_v2() results in a kernel panic. This can be exploited remotely via the network without authentication. The fix introduces a check to ensure checksum.len is not less than XDR_UNIT. Patches are available in stable kernel branches including 6.6.112, 6.12.53, and 6.17.3.

Affected products

  • Linux Linux Kernel 6.3 to 6.17.3

Timeline

  • 2025-11-12: advisory: NVD publication date
  • 2025-08-11: patched: Original patch authored

References

Related threats