PT-2025-51579 · Linux+3 · Linux Kernel+3

Published

2025-08-12

·

Updated

2026-05-07

·

CVE-2025-40363

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue in the IPv6 implementation related to Address Header (AH) output processing. Specifically, the ah6 output() and ah6 output done() functions exhibit field-spanning memory copy warnings when handling extension headers copied to and from IPv6 address fields. This occurs due to the copying of data exceeding the 16-byte address field size, triggering warnings about potential writes beyond the allocated memory. The warnings are identified as false positives because extension headers are intentionally positioned after the IPv6 header in memory. The issue is addressed by correctly copying addresses and extension headers separately, and by introducing helper functions to reduce code duplication. The vulnerable code is located at net/ipv6/ah6.c:439 within the ah6 output() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2026-05105
CVE-2025-40363
ECHO-1130-BE31-32D8
MGASA-2026-0017
MGASA-2026-0018
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8100-1
USN-8116-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu