Junglewise Threat Intelligence

CVE-2025-40158: Linux Kernel use-after-free in IPv6 ip6_output

CVE-2025-40158 · Severity: high · CVSS 8.1 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's IPv6 networking component, which is responsible for handling modern internet traffic. Under specific conditions, the system could attempt to access memory that has already been freed, potentially leading to a system crash or allowing an attacker to execute unauthorized actions. This issue has been resolved in recent kernel updates to ensure stable and secure network operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's IPv6 stack within the ip6_output() function. The flaw stems from improper synchronization when accessing destination device structures (dst_dev). By failing to use Read-Copy-Update (RCU) primitives correctly in ip6_output(), the kernel could reference a network device object after it has been deallocated. An attacker could potentially exploit this race condition to cause a kernel panic or achieve privilege escalation. The fix involves implementing RCU locking in ip6_output() and utilizing dst_dev_rcu() to ensure the device object remains valid during the output process. Patches have been backported to stable kernel branches.

Affected products

  • Linux Linux Kernel 4.13 to 6.17.3

Timeline

  • 2025-08-28: patched: Initial fix authored by Eric Dumazet
  • 2025-11-12: disclosed: CVE published

References

Related threats