Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40186— tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().

CVSS 8.1 · High EPSS 0.54% · P43

Possible ATT&CK Techniques 1AI

T1499.003 · Application Exhaustion Flood

Affected Version Matrix 26

VendorProductVersion RangeStatus
LinuxLinux7ec092a91ff351dcde89c23e795b73a328274db6< e359b742eac1eac75cff4e38ee2e8cea492acd9baffected
a4378dedd6e07e62f2fccb17d78c9665718763d0< ff6a8883f96a5bc74241ce5b3d431a6dcfa2124daffected
33a4fdf0b4a25f8ce65380c3b0136b407ca57609< eb85ad5f23268d64b037bfb545cbcba3752f90c7affected
17d699727577814198d744d6afe54735c6b54c99< 643a94b0cf767325e953591c212be2eb826b9d7faffected
dfd06131107e7b699ef1e2a24ed2f7d17c917753< 422c1c173c39bbbae1e0eaaf8aefe40b2596233baffected
fa4749c065644af4db496b338452a69a3e5147d9< c11ace909e873118295e9eb22dc8c58b0b50eb32affected
45c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c01< 64dc47a13aa3d9daf7cec29b44dca8e22a6aea15affected
45c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c01< 2e7cbbbe3d61c63606994b7ff73c72537afe2e1caffected
… +18 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-40186

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a listener is close()d while a TFO socket is being processed in tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk->sk and calls inet_child_forget(), which calls tcp_disconnect() for the TFO socket. After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(), where reqsk_put() is called due to !reqsk->sk. Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the last req->rsk_refcnt and frees reqsk, and __reqsk_free() at the drop_and_free label causes the refcount underflow for the listener and double-free of the reqsk. Let's remove reqsk_fastopen_remove() in tcp_conn_request(). Note that other callers make sure tp->fastopen_rsk is not NULL. [0]: refcount_t: underflow; use-after-free. WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28) Modules linked in: CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:refcount_warn_saturate (lib/refcount.c:28) Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff <0f> 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6 RSP: 0018:ffffa79fc0304a98 EFLAGS: 00010246 RAX: d83af4db1c6b3900 RBX: ffff9f65c7a69020 RCX: d83af4db1c6b3900 RDX: 0000000000000000 RSI: 00000000ffff7fff RDI: ffffffffac78a280 RBP: 000000009d781b60 R08: 0000000000007fff R09: ffffffffac6ca280 R10: 0000000000017ffd R11: 0000000000000004 R12: ffff9f65c7b4f100 R13: ffff9f65c7d23c00 R14: ffff9f65c7d26000 R15: ffff9f65c7a64ef8 FS: 00007f9f962176c0(0000) GS:ffff9f65fcf00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000200000000180 CR3: 000000000dbbe006 CR4: 0000000000372ef0 Call Trace: <IRQ> tcp_conn_request (./include/linux/refcount.h:400 ./include/linux/refcount.h:432 ./include/linux/refcount.h:450 ./include/net/sock.h:1965 ./include/net/request_sock.h:131 net/ipv4/tcp_input.c:7301) tcp_rcv_state_process (net/ipv4/tcp_input.c:6708) tcp_v6_do_rcv (net/ipv6/tcp_ipv6.c:1670) tcp_v6_rcv (net/ipv6/tcp_ipv6.c:1906) ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:438) ip6_input (net/ipv6/ip6_input.c:500) ipv6_rcv (net/ipv6/ip6_input.c:311) __netif_receive_skb (net/core/dev.c:6104) process_backlog (net/core/dev.c:6456) __napi_poll (net/core/dev.c:7506) net_rx_action (net/core/dev.c:7569 net/core/dev.c:7696) handle_softirqs (kernel/softirq.c:579) do_softirq (kernel/softirq.c:480) </IRQ>
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于tcp_conn_request中错误调用reqsk_fastopen_remove,可能导致引用计数下溢和双重释放。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7ec092a91ff351dcde89c23e795b73a328274db6 ~ e359b742eac1eac75cff4e38ee2e8cea492acd9b -
LinuxLinux 6.17 -

II. Public POCs for CVE-2025-40186

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40186

登录查看更多情报信息。

Patches & Fixes for CVE-2025-40186 (2)

Same Patch Batch · Linux · 2025-11-12 · 96 CVEs total

CVE-2025-401769.8 CRITICALtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-401408.8 HIGHnet: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
CVE-2025-402048.1 HIGHsctp: Fix MAC comparison to be constant-time
CVE-2025-401358.1 HIGHipv6: use RCU in ip6_xmit()
CVE-2025-401588.1 HIGHipv6: use RCU in ip6_output()
CVE-2025-401688.1 HIGHsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-401338.1 HIGHmptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable().
CVE-2025-401418.0 HIGHBluetooth: ISO: Fix possible UAF on iso_conn_free
CVE-2025-401997.8 HIGHpage_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches
CVE-2025-401727.8 HIGHaccel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
CVE-2025-402057.8 HIGHbtrfs: avoid potential out-of-bounds in btrfs_encode_fh()
CVE-2025-402037.8 HIGHlistmount: don't call path_put() under namespace semaphore
CVE-2025-402017.8 HIGHkernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
CVE-2025-401697.8 HIGHbpf: Reject negative offsets for ALU ops
CVE-2025-401657.8 HIGHmedia: nxp: imx8-isi: m2m: Fix streaming cleanup on release
CVE-2025-401667.8 HIGHdrm/xe/guc: Check GuC running state before deregistering exec queue
CVE-2025-401677.8 HIGHext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-401597.8 HIGHxsk: Harden userspace-supplied xdp_desc validation
CVE-2025-401517.8 HIGHLoongArch: BPF: No support of struct argument in trampoline programs
CVE-2025-401497.8 HIGHtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().

Showing top 20 of 96 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40186

No comments yet


Leave a comment