SB20251216186 - Resource management error in Linux kernel ipv6
Published: December 16, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-40363)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the ah6_output_done() and ah6_output() functions in net/ipv6/ah6.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0bf756ae1e69fec5e6332c37830488315d6d771b
- https://git.kernel.org/stable/c/2327a3d6f65ce2fe2634546dde4a25ef52296fec
- https://git.kernel.org/stable/c/2da805a61ef5272a2773775ce14c3650adb84248
- https://git.kernel.org/stable/c/75b16b2755e12999ad850756ddfb88ad4bfc7186
- https://git.kernel.org/stable/c/9bf27de51bd6db5ff827780ec0eba55de230ba45
- https://git.kernel.org/stable/c/b056f971bd72b373b7ae2025a8f3bd18f69653d3
- https://git.kernel.org/stable/c/c14cf41094136691c92ef756872570645d61f4a1
- https://git.kernel.org/stable/c/f28dde240160f3c48a50d641d210ed6a3b9596ed