#VU120142 Resource management error in Linux kernel - CVE-2025-40363
Published: December 16, 2025
Vulnerability identifier: #VU120142
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-40363
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the ah6_output_done() and ah6_output() functions in net/ipv6/ah6.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0bf756ae1e69fec5e6332c37830488315d6d771b
- https://git.kernel.org/stable/c/2327a3d6f65ce2fe2634546dde4a25ef52296fec
- https://git.kernel.org/stable/c/2da805a61ef5272a2773775ce14c3650adb84248
- https://git.kernel.org/stable/c/75b16b2755e12999ad850756ddfb88ad4bfc7186
- https://git.kernel.org/stable/c/9bf27de51bd6db5ff827780ec0eba55de230ba45
- https://git.kernel.org/stable/c/b056f971bd72b373b7ae2025a8f3bd18f69653d3
- https://git.kernel.org/stable/c/c14cf41094136691c92ef756872570645d61f4a1
- https://git.kernel.org/stable/c/f28dde240160f3c48a50d641d210ed6a3b9596ed