Skip to main content

Threats Tagged 'cve-2025-40139'

View all threats tagged with 'cve-2025-40139'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-40139

Threats Tagged 'cve-2025-40139'

Click on any threat for detailed analysis and mitigation recommendations

A use-after-free (UAF) vulnerability in the Linux kernel's smc_clc_prfx_set() function was resolved by changing how socket destination device references are accessed. The flaw involved unsafe use of sk_dst_get(sk)->dev without proper synchronization, which could lead to memory corruption. The fix uses __sk_dst_get() and dst_dev_rcu() under RCU read lock to prevent UAF. This vulnerability affects local attackers with low privileges and can result in high impact on confidentiality, integrity, and availability.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL. Using sk_dst_get(sk)->dev could trigger UAF. Let's use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock() after kernel_getsockname(). Note that the returned value of smc_clc_prfx_set() is not used in the caller. While at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu() not to touch dst there.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2025-40139
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses