CVE-2025-40135
Published Nov 12, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.
Is your site exposed to CVE-2025-40135?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/9085e56501d93af9f2d7bd16f7fcfacdde47b99c
https://git.kernel.org/stable/c/bd0905e2122e3680968cd0741966983490bf2ed3
https://git.kernel.org/stable/c/f0a54d00d2f36de40266f47c27989853e8588656
https://git.kernel.org/stable/c/f69fec6287565fdeb61f65e700a1184352306943
https://git.kernel.org/stable/c/f7f9e924f23684b4b23cd9f976cceab24a968e34
Frequently Asked Questions
What is CVE-2025-40135? +
In the Linux kernel, the following vulnerability has been resolved:
ipv6: use RCU in ip6_xmit()
Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent
possible UAF.
How do I check if I'm vulnerable to CVE-2025-40135? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.