sctp: Fix MAC comparison to be constant-time
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40204
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/b93fa8dc521d00d2d44bf034fb90e0d79b036617
- https://git.kernel.org/stable/c/0e8b8c326c2a6de4d837b1bb034ea704f4690d77
- https://git.kernel.org/stable/c/1cd60e0d0fb8f0e62ec4499138afce6342dc9d4c
- https://git.kernel.org/stable/c/9c05d44ec24126fc283835b68f82dba3ae985209
- https://git.kernel.org/stable/c/ed3044b9c810c5c24eb2830053fbfe5fd134c5d4
- https://git.kernel.org/stable/c/8019b3699289fce3f10b63f98601db97b8d105b0
- https://git.kernel.org/stable/c/0b32ff285ff6f6f1ac1d9495787ccce8837d6405
- https://git.kernel.org/stable/c/dd91c79e4f58fbe2898dac84858033700e0e99fb
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.