Wind River Support Network

HomeDefectsLIN1023-16834
Acknowledged

LIN1023-16834 : Security Advisory - linux - CVE-2025-40173

Created: Nov 12, 2025    Updated: Nov 26, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]net/ip6_tunnel: Prevent perpetual tunnel growth[EOL][EOL]Similarly to ipv4 tunnel, ipv6 version updates dev->needed_headroom, too.[EOL]While ipv4 tunnel headroom adjustment growth was limited in[EOL]commit 5ae1e9922bbd ("net: ip_tunnel: prevent perpetual headroom growth"),[EOL]ipv6 tunnel yet increases the headroom without any ceiling.[EOL][EOL]Reflect ipv4 tunnel headroom adjustment limit on ipv6 version.[EOL][EOL]Credits to Francesco Ruggeri, who was originally debugging this issue[EOL]and wrote local Arista-specific patch and a reproducer.
Live chat
Online