Answer in brief
CVE-2025-40187 records a Unknown severity vulnerability in net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-40187 records a Unknown severity vulnerability in net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <1014b83778c8677f1d7a57c26dc728baa801ac62 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <7f702f85df0266ed7b5bab81ba50394c92f3c928 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <dbceedc0213e75bf3e9f9f9e2f66b10699d004fe || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <025419f4e216a3ae0d0cec622262e98e8078c447 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <c21f45cfa4a9526b34d76b397c9ef080668b6e73 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <d0e8f1445c19b1786759ba72a38267e1449bab7e || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <badbd79313e6591616c1b78e29a9b71efed7f035 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <2f3119686ef50319490ccaec81a575973da98815 | 1014b83778c8677f1d7a57c26dc728baa801ac62, 7f702f85df0266ed7b5bab81ba50394c92f3c928, dbceedc0213e75bf3e9f9f9e2f66b10699d004fe, 025419f4e216a3ae0d0cec622262e98e8078c447, c21f45cfa4a9526b34d76b397c9ef080668b6e73, d0e8f1445c19b1786759ba72a38267e1449bab7e, badbd79313e6591616c1b78e29a9b71efed7f035, 2f3119686ef50319490ccaec81a575973da98815 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() If new_asoc->peer.adaptation_ind=0 and sctp_ulpevent_make_authkey=0 and sctp_ulpevent_make_authkey() returns 0, then the variable ai_ev remains zero and the zero will be dereferenced in the sctp_ulpevent_free() function.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <1014b83778c8677f1d7a57c26dc728baa801ac62 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <7f702f85df0266ed7b5bab81ba50394c92f3c928 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <dbceedc0213e75bf3e9f9f9e2f66b10699d004fe || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <025419f4e216a3ae0d0cec622262e98e8078c447 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <c21f45cfa4a9526b34d76b397c9ef080668b6e73 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <d0e8f1445c19b1786759ba72a38267e1449bab7e || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <badbd79313e6591616c1b78e29a9b71efed7f035 || >=30f6ebf65bc46161c5aaff1db2e6e7c76aa4a06b <2f3119686ef50319490ccaec81a575973da98815 | 1014b83778c8677f1d7a57c26dc728baa801ac62, 7f702f85df0266ed7b5bab81ba50394c92f3c928, dbceedc0213e75bf3e9f9f9e2f66b10699d004fe, 025419f4e216a3ae0d0cec622262e98e8078c447, c21f45cfa4a9526b34d76b397c9ef080668b6e73, d0e8f1445c19b1786759ba72a38267e1449bab7e, badbd79313e6591616c1b78e29a9b71efed7f035, 2f3119686ef50319490ccaec81a575973da98815 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Nov 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() If new_asoc->peer.adaptation_ind=0 and sctp_ulpevent_make_authkey=0 and sctp_ulpevent_make_authkey() returns 0, then the variable ai_ev remains zero and the zero will be dereferenced in the sctp_ulpevent_free() function.
Quoted source text, attributed separately from HOL analysis.