Home

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-12 | Updated 2025-12-01 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before b93fa8dc521d00d2d44bf034fb90e0d79b036617
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 0e8b8c326c2a6de4d837b1bb034ea704f4690d77
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 9c05d44ec24126fc283835b68f82dba3ae985209
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before ed3044b9c810c5c24eb2830053fbfe5fd134c5d4
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 8019b3699289fce3f10b63f98601db97b8d105b0
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 0b32ff285ff6f6f1ac1d9495787ccce8837d6405
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before dd91c79e4f58fbe2898dac84858033700e0e99fb
affected

Default status
affected

2.6.12
affected

Any version before 2.6.12
unaffected

5.4.301 (semver)
unaffected

5.10.246 (semver)
unaffected

5.15.195 (semver)
unaffected

6.1.157 (semver)
unaffected

6.6.113 (semver)
unaffected

6.12.54 (semver)
unaffected

6.17.4 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/b93fa8dc521d00d2d44bf034fb90e0d79b036617

git.kernel.org/...c/0e8b8c326c2a6de4d837b1bb034ea704f4690d77

git.kernel.org/...c/1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c

git.kernel.org/...c/9c05d44ec24126fc283835b68f82dba3ae985209

git.kernel.org/...c/ed3044b9c810c5c24eb2830053fbfe5fd134c5d4

git.kernel.org/...c/8019b3699289fce3f10b63f98601db97b8d105b0

git.kernel.org/...c/0b32ff285ff6f6f1ac1d9495787ccce8837d6405

git.kernel.org/...c/dd91c79e4f58fbe2898dac84858033700e0e99fb

cve.org (CVE-2025-40204)

nvd.nist.gov (CVE-2025-40204)

Download JSON