CVE-2025-40149

tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().

References

Notes

 carnil> Introduced in e8f69799810c ("net/tls: Add generic NIC offload infrastructure").
 carnil> Vulnerable versions: 4.18.

Bugs

Status

Branch Status
upstream released (6.18-rc1) [c65f27b9c3be2269918e1cbad6d8884741f835c5]
6.19-upstream-stable N/A "Fixed before branching point"
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable released (6.17.3) [feb474ddbf26b51f462ae2e60a12013bdcfc5407]
6.12-upstream-stable released (6.12.66) [f09cd209359a23f88d4f3fa3d2379d057027e53c]
6.6-upstream-stable released (6.6.121) [13159c7125636371543a82cb7bbae00ab36730cc]
6.1-upstream-stable released (6.1.161) [e37ca0092ddace60833790b4ad7a390408fb1be9]
5.10-upstream-stable needed
sid released (6.17.6-1)
6.12-trixie-security released (6.12.69-1)
6.1-bookworm-security released (6.1.162-1)
5.10-bullseye-security needed