Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40158

12
FAUCET Score

CVE-2025-40158 addresses a Use-After-Free (UAF) vulnerability in the Linux kernel's IPv6 output function (ip6_output()). This flaw is resolved by implementing RCU (Read-Copy-Update) to safely manage data structures. While no CVSS score is available, the FAUCET Risk Score is low at 5/100, suggesting a limited potential impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
4.13CNA affecteddefault affected
LinuxLinux
>= 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36, < 0393f85c3241c19ba8550f04a812e7d19f6b3082, >= 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36, < 11709573cc4e48dc34c80fc7ab9ce5b159e29695CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel-0:6.12.0-124.31.1.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.104.1.rt7.445.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.104.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-611.30.1.el9_7
View patch
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40158Moderate

kernel: ipv6: use RCU in ip6_output()

Nov 12, 2025
microsoft2025-Nov/CVE-2025-40158Moderate

ipv6: use RCU in ip6_output()

Nov 11, 2025

References

git.kernel.org / stable/c/0393f85c3241c19ba8550f04a812e7d19f6b3082
git.kernel.org / stable/c/11709573cc4e48dc34c80fc7ab9ce5b159e29695