CVE-2025-40158
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2025
Last modified:
12/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipv6: use RCU in ip6_output()<br />
<br />
Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent<br />
possible UAF.<br />
<br />
We can remove rcu_read_lock()/rcu_read_unlock() pairs<br />
from ip6_finish_output2().



