CVE-2025-40278
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/12/2025
Última modificación:
06/12/2025
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak<br />
<br />
Fix a KMSAN kernel-infoleak detected by the syzbot .<br />
<br />
[net?] KMSAN: kernel-infoleak in __skb_datagram_iter<br />
<br />
In tcf_ife_dump(), the variable &#39;opt&#39; was partially initialized using a<br />
designatied initializer. While the padding bytes are reamined<br />
uninitialized. nla_put() copies the entire structure into a<br />
netlink message, these uninitialized bytes leaked to userspace.<br />
<br />
Initialize the structure with memset before assigning its fields<br />
to ensure all members and padding are cleared prior to beign copied.<br />
<br />
This change silences the KMSAN report and prevents potential information<br />
leaks from the kernel memory.<br />
<br />
This fix has been tested and validated by syzbot. This patch closes the<br />
bug reported at the following syzkaller link and ensures no infoleak.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2191662058443e0bcc28d11694293d8339af6dde
- https://git.kernel.org/stable/c/37f0680887c5aeba9a433fe04b35169010568bb1
- https://git.kernel.org/stable/c/5e3644ef147bf7140259dfa4cace680c9b26fe8b
- https://git.kernel.org/stable/c/918e063304f945fb93be9bb70cacea07d0b730ea
- https://git.kernel.org/stable/c/a676a296af65d33725bdf7396803180957dbd92e
- https://git.kernel.org/stable/c/c8f51dad94cbb88054e2aacc272b3ce1ed11fb1e
- https://git.kernel.org/stable/c/ce50039be49eea9b4cd8873ca6eccded1b4a130a
- https://git.kernel.org/stable/c/d1dbbbe839647486c9b893e5011fe84a052962df



