CVE-2025-40337 addresses a flaw in the Linux kernel's stmmac network driver where hardware checksum offload errors were not properly handled, potentially allowing corrupt packets to be passed as valid. This vulnerability affects Linux systems utilizing the stmmac driver. The severity is moderate, as it requires specific network configurations and packet manipulation to exploit, with the primary impact being data corruption rather than direct system compromise. No CVSS score is available, but its FAUCET Risk Score is 7/100. There is currently no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.2CNA affecteddefault affected | |
| Linux | Linux | >= 3c20f72f9108b2fcf30ec63d8a4203736c01ccd0, < 1aa319e0f12d2d761a31556b82a5852c98eb0bea, >= 3c20f72f9108b2fcf30ec63d8a4203736c01ccd0, < 63fbe0e6413279d5ea5842e2423e351ded547683, >= 3c20f72f9108b2fcf30ec63d8a4203736c01ccd0, < 719fcdf29051f7471d5d433475af76219019d33d, >= 3c20f72f9108b2fcf30ec63d8a4203736c01ccd0, < ee0aace5f844ef59335148875d05bec8764e71e8CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026Linux kernel (Azure) vulnerabilities
Feb 24, 2026net: stmmac: Correctly handle Rx checksum offload errors
Dec 9, 2025kernel: net: stmmac: Correctly handle Rx checksum offload errors
Dec 9, 2025