CVE-2025-40331

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sctp: Prevent TOCTOU out-of-bounds write<br /> <br /> For the following path not holding the sock lock,<br /> <br /> sctp_diag_dump() -&gt; sctp_for_each_endpoint() -&gt; sctp_ep_dump()<br /> <br /> make sure not to exceed bounds in case the address list has grown<br /> between buffer allocation (time-of-check) and write (time-of-use).

Impact