Review reviewHigh

CVE-2025-40043

Linux

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-tools-fixes-for-v6.17-2025-09-16' of git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools"). This bug arises due to very limited and poor input validation that was done at nic_valid_size(). This validation only validates the skb->len (directly reflects size provided at the userspace interface) with the length provided in the buffer itself (...

CVSS
8.8
EPSS
0.29%
21.5% percentile
CISA KEV
Not listed
Published
2025.10.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-tools-fixes-for-v6.17-2025-09-16' of git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools"). This bug arises due to very limited and poor input validation that was done at nic_valid_size(). This validation only validates the skb->len (directly reflects size provided at the userspace interface) with the length provided in the buffer itself (...

Affected product and versions

Product
Linux
Affected versions
>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 8fcc7315a10a84264e55bb65ede10f0af20a983f, >= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < bfdda0123dde406dbff62e7e9136037e97998a15, >= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 0ba68bea1e356f466ad29449938bea12f5f3711f, >= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 74837bca0748763a77f77db47a0bdbe63b347628, >= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < c395d1e548cc68e84584ffa2e3ca9796a78bf7b9, >= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 9c328f54741bd5465ca1dc717c84c04242fac2e1, >= 3.2
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-40043 — Linux | SECUFOCUS NOW