CVE-2025-21640 is a null pointer dereference vulnerability in the Linux kernel's SCTP module, specifically related to how the 'cookie_hmac_alg' sysctl handles network namespace information. This flaw can lead to a kernel crash (Oops) when the 'current->nsproxy' is NULL, such as during task exit. Rated as Medium severity (CVSS 5.5), it requires local access and low privileges to achieve a denial of service. There is currently no known exploit code available, and it has not been observed in active exploitation, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8, < 6.1.125CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.72CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025kernel: sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
Jan 19, 2025sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
Jan 14, 2025