CVE-2025-39702

ipv6: sr: Fix MAC comparison to be constant-time

References

Notes

 carnil> Introduced in bf355b8d2c30 ("ipv6: sr: add core files for SR HMAC support").
 carnil> Vulnerable versions: 4.10.

Bugs

Status

Branch Status
upstream released (6.17-rc3) [a458b2902115b26a25d67393b12ddd57d1216aaa]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.4) [f7878d47560d61e3f370aca3cebb8f42a55b990a]
6.12-upstream-stable released (6.12.44) [b3967c493799e63f648e9c7b6cb063aa2aed04e7]
6.6-upstream-stable released (6.6.103) [3ddd55cf19ed6cc62def5e3af10c2a9df1b861c3]
6.1-upstream-stable released (6.1.149) [86b6d34717fe0570afce07ee79b8eeb40341f831]
5.10-upstream-stable needed
sid released (6.16.5-1)
6.12-trixie-security released (6.12.48-1)
6.1-bookworm-security released (6.1.153-1)
5.10-bullseye-security needed