# CVE-2025-40074

## Summary

- **CVE ID:** CVE-2025-40074
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Oct 28, 2025
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ipv4: start using dst_dev_rcu()

Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.

Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(),
ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().

## Affected Products

- Linux — Linux (4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36)
- Linux — Linux (4.13)
- Linux — Linux (0)
- Linux — Linux (6.17.3)
- Linux — Linux (6.18)
- Linux — Linux (6.12.106)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/923e0734c386984d45de508528a7a7ad91d791cc)
- [CNA](https://git.kernel.org/stable/c/6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8)
- [CNA](https://git.kernel.org/stable/c/684efb2c86c887685f9aa65e1a21b3df6c1f822d)
- [CNA](https://git.kernel.org/stable/c/e150f273cd8ed34ebc6d03758aad95c12fc58337)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.43%
- **EPSS Percentile:** 36.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._