SB2025102606 - Input validation error in Linux kernel crypto
Published: October 26, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-40022)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the include/crypto/if_alg.h. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/316b090c2fee964c307a634fecc7df269664b158
- https://git.kernel.org/stable/c/3a21698ace915a445bce2d0dcfc84b6d2199baf7
- https://git.kernel.org/stable/c/54506c6335690f4ef1b9f154e34f5a604c72c1ed
- https://git.kernel.org/stable/c/8703940bd30b5ad94408d28d7192db2491cd3592
- https://git.kernel.org/stable/c/d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb
- https://git.kernel.org/stable/c/d382d6daf0184490f366562469a5673f65ee2662
- https://git.kernel.org/stable/c/fbe96bd25423e61273d8831e995260b429d850b6