CVE-2025-40176
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2025
Last modified:
12/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tls: wait for pending async decryptions if tls_strp_msg_hold fails<br />
<br />
Async decryption calls tls_strp_msg_hold to create a clone of the<br />
input skb to hold references to the memory it uses. If we fail to<br />
allocate that clone, proceeding with async decryption can lead to<br />
various issues (UAF on the skb, writing into userspace memory after<br />
the recv() call has returned).<br />
<br />
In this case, wait for all pending decryption requests.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/39dec4ea3daf77f684308576baf483b55ca7f160
- https://git.kernel.org/stable/c/4fc109d0ab196bd943b7451276690fb6bb48c2e0
- https://git.kernel.org/stable/c/9f83fd0c179e0f458e824e417f9d5ad53443f685
- https://git.kernel.org/stable/c/b8a6ff84abbcbbc445463de58704686011edc8e1
- https://git.kernel.org/stable/c/c61d4368197d65c4809d9271f3b85325a600586a



