In the Linux kernel, the following vulnerability has been resolved:
net/sctp: fix a null dereference in sctpdisposition sctpsfdo51Dce()
If newasoc->peer.adaptationind=0 and sctpulpeventmakeauthkey=0 and sctpulpeventmakeauthkey() returns 0, then the variable aiev remains zero and the zero will be dereferenced in the sctpulpevent_free() function.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/40xxx/CVE-2025-40187.json"
}