-

CVE-2025-40204

In the Linux kernel, the following vulnerability has been resolved:

sctp: Fix MAC comparison to be constant-time

To prevent timing attacks, MACs need to be compared in constant time.
Use the appropriate helper function for this.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < b93fa8dc521d00d2d44bf034fb90e0d79b036617
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 0e8b8c326c2a6de4d837b1bb034ea704f4690d77
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 9c05d44ec24126fc283835b68f82dba3ae985209
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < ed3044b9c810c5c24eb2830053fbfe5fd134c5d4
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 8019b3699289fce3f10b63f98601db97b8d105b0
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 0b32ff285ff6f6f1ac1d9495787ccce8837d6405
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < dd91c79e4f58fbe2898dac84858033700e0e99fb
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version < 2.6.12
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.301
Status unaffected
Version <= 5.10.*
Version 5.10.246
Status unaffected
Version <= 5.15.*
Version 5.15.195
Status unaffected
Version <= 6.1.*
Version 6.1.157
Status unaffected
Version <= 6.6.*
Version 6.6.113
Status unaffected
Version <= 6.12.*
Version 6.12.54
Status unaffected
Version <= 6.17.*
Version 6.17.4
Status unaffected
Version <= *
Version 6.18
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.193
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String