In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). (CVE-2025-40280)
A use-after-free vulnerability in the Linux kernel's TIPC subsystem was identified and resolved. The flaw occurs in the function tipc_mon_reinit_self(), which accesses an array without proper locking, leading to potential memory corruption. This issue was reported by syzbot and involves improper synchronization with the RTNL lock. The vulnerability has been fixed by ensuring the RTNL lock is held during the relevant operation.
AI Analysis
Technical Summary
The Linux kernel contained a use-after-free vulnerability in the tipc_mon_reinit_self() function of the TIPC (Transparent Inter-Process Communication) subsystem. The function iterated over the tipc_net(net)->monitors[] array without holding the RTNL lock, although the array is protected by RTNL. This improper locking led to a use-after-free condition detected by KASAN, as tipc_mon_reinit_self() is called from tipc_net_finalize(), which is generally protected by RTNL except when called from tipc_net_finalize_work(). The fix involved holding the RTNL lock in tipc_net_finalize_work() to prevent concurrent access issues.
Potential Impact
This vulnerability allows a local attacker with limited privileges to cause a use-after-free condition in kernel memory, potentially leading to memory corruption. The CVSS vector indicates high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), meaning exploitation could result in full system compromise or denial of service. However, exploitation requires local access and limited privileges.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by ensuring the RTNL lock is held during the execution of tipc_mon_reinit_self() when called from tipc_net_finalize_work(). Users should update their Linux kernel to a version that includes this fix. Patch status is not explicitly provided here; check the official Linux kernel advisories or vendor updates for the fixed kernel version and apply the update accordingly.
In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). (CVE-2025-40280)
Description
A use-after-free vulnerability in the Linux kernel's TIPC subsystem was identified and resolved. The flaw occurs in the function tipc_mon_reinit_self(), which accesses an array without proper locking, leading to potential memory corruption. This issue was reported by syzbot and involves improper synchronization with the RTNL lock. The vulnerability has been fixed by ensuring the RTNL lock is held during the relevant operation.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel contained a use-after-free vulnerability in the tipc_mon_reinit_self() function of the TIPC (Transparent Inter-Process Communication) subsystem. The function iterated over the tipc_net(net)->monitors[] array without holding the RTNL lock, although the array is protected by RTNL. This improper locking led to a use-after-free condition detected by KASAN, as tipc_mon_reinit_self() is called from tipc_net_finalize(), which is generally protected by RTNL except when called from tipc_net_finalize_work(). The fix involved holding the RTNL lock in tipc_net_finalize_work() to prevent concurrent access issues.
Potential Impact
This vulnerability allows a local attacker with limited privileges to cause a use-after-free condition in kernel memory, potentially leading to memory corruption. The CVSS vector indicates high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), meaning exploitation could result in full system compromise or denial of service. However, exploitation requires local access and limited privileges.
Mitigation Recommendations
A fix has been implemented in the Linux kernel by ensuring the RTNL lock is held during the execution of tipc_mon_reinit_self() when called from tipc_net_finalize_work(). Users should update their Linux kernel to a version that includes this fix. Patch status is not explicitly provided here; check the official Linux kernel advisories or vendor updates for the fixed kernel version and apply the update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p7jc-87rf-j283
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-40280"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d49c2644c7f8479531
Added to database: 07/30/2026, 15:50:44 UTC
Last enriched: 07/30/2026, 17:39:28 UTC
Last updated: 09/10/2026, 19:38:44 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.