CVE-2025-40187

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-40187
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40187.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40187
Downstream
Published
2025-11-12T21:56:29.504Z
Modified
2025-11-27T02:33:14.612222Z
Summary
net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sctp: fix a null dereference in sctpdisposition sctpsfdo51Dce()

If newasoc->peer.adaptationind=0 and sctpulpeventmakeauthkey=0 and sctpulpeventmakeauthkey() returns 0, then the variable aiev remains zero and the zero will be dereferenced in the sctpulpevent_free() function.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/40xxx/CVE-2025-40187.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
1014b83778c8677f1d7a57c26dc728baa801ac62
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
7f702f85df0266ed7b5bab81ba50394c92f3c928
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
dbceedc0213e75bf3e9f9f9e2f66b10699d004fe
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
025419f4e216a3ae0d0cec622262e98e8078c447
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
c21f45cfa4a9526b34d76b397c9ef080668b6e73
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
d0e8f1445c19b1786759ba72a38267e1449bab7e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
badbd79313e6591616c1b78e29a9b71efed7f035
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b
Fixed
2f3119686ef50319490ccaec81a575973da98815

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.17.0
Fixed
5.4.301
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.246
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.195
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.157
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.113
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.54
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.4