bpf: Explicitly check accesses to bpf_sock_addr

Summary

CVECVE-2025-40078
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-10-28 12:15:42 UTC
Updated2026-07-14 13:17:52 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Syzkaller found a kernel warning on the following sock_addr program: 0: r0 = 0 1: r2 = *(u32 *)(r1 +60) 2: exit which triggers: verifier bug: error during ctx access conversion (0) This is happening because offset 60 in bpf_sock_addr corresponds to an implicit padding of 4 bytes, right after msg_src_ip4. Access to this padding isn't rejected in sock_addr_is_valid_access and it thus later fails to convert the access. This patch fixes it by explicitly checking the various fields of bpf_sock_addr in sock_addr_is_valid_access. I checked the other ctx structures and is_valid_access functions and didn't find any other similar cases. Other cases of (properly handled) padding are covered in new tests in a subsequent patch.

Risk And Classification

EPSS: 0.001970000 probability, percentile 0.095870000 (date 2026-07-14)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 de44cdc50d2dce8718cb57deddf9cf1be9a7759f git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 76e04bbb4296fb6eac084dbfc27e02ccc744db3e git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 4f00858cd9bbbdf67159e28b85a8ca9e77c83622 git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 cdeafacb4f9ff261a96baef519e29480fd7b1019 git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 fe9d33f0470350558cb08cecb54cf2267b3a45d2 git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69 git Not specified
CNA Linux Linux affected 1cedee13d25ab118d325f95588c1a084e9317229 6fabca2fc94d33cdf7ec102058983b086293395f git Not specified
CNA Linux Linux affected 4.18 Not specified
CNA Linux Linux unaffected 4.18 semver Not specified
CNA Linux Linux unaffected 5.4.301 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.246 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.195 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.156 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.112 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.53 6.12.* semver Not specified
CNA Linux Linux unaffected 6.17.3 6.17.* semver Not specified
CNA Linux Linux unaffected 6.18 * original_commit_for_fix Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/de44cdc50d2dce8718cb57deddf9cf1be9a7759f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4f00858cd9bbbdf67159e28b85a8ca9e77c83622 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
cert-portal.siemens.com/productcert/html/ssa-019113.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/cdeafacb4f9ff261a96baef519e29480fd7b1019 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6fabca2fc94d33cdf7ec102058983b086293395f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/76e04bbb4296fb6eac084dbfc27e02ccc744db3e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fe9d33f0470350558cb08cecb54cf2267b3a45d2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report