CVE-2025-40253
Published Dec 4, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd_sweep_req(mpcginfo)' is called conditionally from function 'ctcmpc_unpack_skb'. It frees passed mpcginfo. After that a call to function 'kfree' in function 'ctcmpc_unpack_skb' frees it again. Remove 'kfree' call in function 'mpc_rcvd_sweep_req(mpcginfo)'. Bug detected by the clang static analyzer.
Is your site exposed to CVE-2025-40253?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/06f1dd1de0d33dbfbd2e1fc9fc57d8895f730de2
https://git.kernel.org/stable/c/3b177b2ded563df16f6d5920671ffcfe5915d472
https://git.kernel.org/stable/c/43096dab8cc60fc39133205fd149a54d3acebea8
https://git.kernel.org/stable/c/6bf8ccaabce8cebb6cb1f255c93d0acdfe95c17a
https://git.kernel.org/stable/c/7616e2eee679746d526c7f5befd4eedb995935b5
https://git.kernel.org/stable/c/7ff76f8dc6b550f8d16487bf3cebc278be720b5c
https://git.kernel.org/stable/c/b9dbfb1b5699f9f1e4991f96741bdf9047147589
https://git.kernel.org/stable/c/da02a1824884d6c84c5e5b5ac373b0c9e3288ec2
Frequently Asked Questions
What is CVE-2025-40253? +
In the Linux kernel, the following vulnerability has been resolved:
s390/ctcm: Fix double-kfree
The function 'mpc_rcvd_sweep_req(mpcginfo)' is called conditionally
from function 'ctcmpc_unpack_skb'. It frees passed mpcginfo.
After that a call to function 'kfree' in function 'ctcmpc_unpack_skb'
frees it again.
Remove 'kfree' call in function 'mpc_rcvd_sweep_req(mpcginfo)'.
Bug detected by the clang static analyzer.
How do I check if I'm vulnerable to CVE-2025-40253? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.