CVE-2025-40043
Last modified
CVE-2025-40043 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-tools-fixes-for-v6.17-2025-09-16' of git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools"). This bug arises due to very limited and poor input validation that was done at nic_valid_size(). This validation only validates the skb->len (directly reflects size provided at the userspace interface) with the length provided in the buffer itself (interpreted as NCI_HEADER). EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-tools-fixes-for-v6.17-2025-09-16' of git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools"). This bug arises due to very limited and poor input validation that was done at nic_valid_size(). This validation only validates the skb->len (directly reflects size provided at the userspace interface) with the length provided in the buffer itself (interpreted as NCI_HEADER). This leads to the processing of memory content at the address assuming the correct layout per what opcode requires there. This leads to the accesses to buffer of `skb_buff->data` which is not assigned anything yet. Following the same silent drop of packets of invalid sizes at `nic_valid_size()`, add validation of the data in the respective handlers and return error values in case of failure. Release the skb if error values are returned from handlers in `nci_nft_packet` and effectively do a silent drop Possible TODO: because we silently drop the packets, the call to `nci_request` will be waiting for completion of request and will face timeouts. These timeouts can get excessively logged in the dmesg. A proper handling of them may require to export `nci_request_cancel` (or propagate error handling from the nft packets handlers).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < 8fcc7315a10a84264e55bb65ede10f0af20a983f; >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < bfdda0123dde406dbff62e7e9136037e97998a15; >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < 0ba68bea1e356f466ad29449938bea12f5f3711f; >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < 74837bca0748763a77f77db47a0bdbe63b347628; >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < c395d1e548cc68e84584ffa2e3ca9796a78bf7b9; >= 6a2968aaf50c7a22fced77a5e24aa636281efca8, < 9c328f54741bd5465ca1dc717c84c04242fac2e1 |
| Linux | Linux | 3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40043?
How severe is CVE-2025-40043?
How do I fix CVE-2025-40043?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40038In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-40039In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2025-4004A vulnerability was found in PHPGurukul COVID19 Testing Mana…9.8
- CVE-2025-40040In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-40041In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40042In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40044In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40045In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40046In the Linux kernel, the following vulnerability has been re…8.6
- CVE-2025-40047In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40048In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-40049In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
