CVE-2025-40281
Last modified
CVE-2025-40281 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are setting very large rto_alpha and/or rto_beta. In order to prevent user regression, perform the test at run time. Also add READ_ONCE() annotations as sysctl values can change under us. [1] UBSAN: shift-out-of-bounds in net/sctp/transport.c:509:41 shift exponent 64 is too large for 32-bit type 'unsigned int' CPU: 0 UID: 0 PID: 16704 Comm: syz.2.2320 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x16c/0x1f0 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:233 [inline] __ubsan_handle_shift_out_of_bounds+0x27f/0x420 lib/ubsan.c:494 sctp_transport_update_rto.cold+0x1c/0x34b net/sctp/transport.c:509 sctp_check_transmitted+0x11c4/0x1c30 net/sctp/outqueue.c:1502 sctp_outq_sack+0x4ef/0x1b20 net/sctp/outqueue.c:1338 sctp_cmd_process_sack net/sctp/sm_sideeffect.c:840 [inline] sctp_cmd_interpreter net/sctp/sm_sideeffect.c:1372 [inline]
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < 0e0413e3315199b23ff4aec295e256034cd0a6e4; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < 834e65be429c0fa4f9bb5945064bd57f18ed2187; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < abb086b9a95d0ed3b757ee59964ba3c4e4b2fc1a; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < d0d858652834dcf531342c82a0428170aa7c2675; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < ed71f801249d2350c77a73dca2c03918a15a62fe; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < 1cfa4eac275cc4875755c1303d48a4ddfe507ca8; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < aaba523dd7b6106526c24b1fd9b5fc35e5aaa88d; >= b58537a1f5629bdc98a8b9dc2051ce0e952f6b4b, < 1534ff77757e44bcc4b98d0196bc5c0052fce5fa |
| Linux | Linux | 3.16 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40281?
How severe is CVE-2025-40281?
How do I fix CVE-2025-40281?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40276In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2025-40277In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40278In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40279In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4028A vulnerability has been found in PHPGurukul COVID19 Testing…9.8
- CVE-2025-40280In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40282In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40283In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40284In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40285In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2025-40286In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40287In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-40281?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
