Junglewise Threat Intelligence

CVE-2025-40149: Linux Kernel use-after-free in TLS get_netdev_for_sock

CVE-2025-40149 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability has been identified in the Linux kernel's Transport Layer Security (TLS) implementation. The issue occurs when the system attempts to identify the network hardware associated with a secure connection, potentially leading to a system crash or unauthorized memory access. This could allow a local user to disrupt system operations or potentially gain elevated privileges on the affected device.

Technical details

A use-after-free (UAF) vulnerability exists in net/tls/tls_device.c within the Linux kernel. The function get_netdev_for_sock() is invoked during setsockopt() operations without proper RCU (Read-Copy-Update) protection. By accessing sk_dst_get(sk)->dev outside of an RCU critical section, the kernel may reference a network device object that has already been freed. An attacker with local access can exploit this race condition to trigger a kernel panic (DoS) or potentially execute arbitrary code in kernel mode. The fix involves implementing proper RCU locking and using __sk_dst_get() and dst_dev_rcu() to safely retrieve the network device reference.

Affected products

  • Linux Linux 4.18 to 6.11.y
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-09-16: disclosed: Initial patch submitted by Kuniyuki Iwashima
  • 2025-11-12: advisory: CVE published

References

Related threats