CNNVD-202511-1456 Information

CNNVD ID

CNNVD-202511-1456

CVE-2025-40149

  • CNNVD Published: 2025-11-12

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于get_netdev_for_sock函数在非RCU环境下使用sk_dst_get(sk)->dev,可能导致释放后重用。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux Kernel has a security loophole, which stems from the use of ssk dst get(sk)->dev in non-RCU environments by the Get netdev for sock function, which may lead to post-release reuse.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-11-12

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/c65f27b9c3be2269918e1cbad6d8884741f835c5 https://git.kernel.org/stable/c/feb474ddbf26b51f462ae2e60a12013bdcfc5407 https://vigilance.fr/vulnerability/Linux-kernel-multiple-vulnerabilities-dated-12-11-2025-48734

Patch

https://www.kernel.org/

Share on: