Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-40236

11
FAUCET Score

CVE-2025-40236 is a Linux kernel vulnerability affecting virtio-net when GSO tunnel is negotiated. It involves a failure to zero unused rxhash fields during tunnel metadata initialization, potentially leading to information leakage. While no CVSS score is available, its FAUCET Risk Score is low at 7/100, and its EPSS score is very low, indicating minimal exploitability. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
6.17CNA affecteddefault affected
LinuxLinux
>= a2fb4bc4e2a6a031683910d85b278c1d25ae5420, < b2284768c6b32aa224ca7d0ef0741beb434f03aa, >= a2fb4bc4e2a6a031683910d85b278c1d25ae5420, < b625d231c66a6041e98817ffc944bf6e4c45b2e3CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (1)

ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1008.8

Vendor Advisories (2)

ubuntuUSN-8029-3

Linux kernel (Azure) vulnerabilities

Feb 24, 2026
redhatCVE-2025-40236

kernel: virtio-net: zero unused hash fields

Dec 4, 2025

References

git.kernel.org / stable/c/b2284768c6b32aa224ca7d0ef0741beb434f03aa
git.kernel.org / stable/c/b625d231c66a6041e98817ffc944bf6e4c45b2e3