{"api_version":"1","generated_at":"2026-07-23T15:16:26+00:00","cve":"CVE-2025-40078","urls":{"html":"https://cve.report/CVE-2025-40078","api":"https://cve.report/api/cve/CVE-2025-40078.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-40078","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-40078"},"summary":{"title":"bpf: Explicitly check accesses to bpf_sock_addr","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n    0: r0 = 0\n    1: r2 = *(u32 *)(r1 +60)\n    2: exit\n\nwhich triggers:\n\n    verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn't rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn't find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.","state":"PUBLISHED","assigner":"Linux","published_at":"2025-10-28 12:15:42","updated_at":"2026-07-14 13:17:52"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/de44cdc50d2dce8718cb57deddf9cf1be9a7759f","name":"https://git.kernel.org/stable/c/de44cdc50d2dce8718cb57deddf9cf1be9a7759f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69","name":"https://git.kernel.org/stable/c/ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4f00858cd9bbbdf67159e28b85a8ca9e77c83622","name":"https://git.kernel.org/stable/c/4f00858cd9bbbdf67159e28b85a8ca9e77c83622","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cdeafacb4f9ff261a96baef519e29480fd7b1019","name":"https://git.kernel.org/stable/c/cdeafacb4f9ff261a96baef519e29480fd7b1019","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6fabca2fc94d33cdf7ec102058983b086293395f","name":"https://git.kernel.org/stable/c/6fabca2fc94d33cdf7ec102058983b086293395f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec","name":"https://git.kernel.org/stable/c/6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/76e04bbb4296fb6eac084dbfc27e02ccc744db3e","name":"https://git.kernel.org/stable/c/76e04bbb4296fb6eac084dbfc27e02ccc744db3e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fe9d33f0470350558cb08cecb54cf2267b3a45d2","name":"https://git.kernel.org/stable/c/fe9d33f0470350558cb08cecb54cf2267b3a45d2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-40078","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40078","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 de44cdc50d2dce8718cb57deddf9cf1be9a7759f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 76e04bbb4296fb6eac084dbfc27e02ccc744db3e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 4f00858cd9bbbdf67159e28b85a8ca9e77c83622 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 cdeafacb4f9ff261a96baef519e29480fd7b1019 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 fe9d33f0470350558cb08cecb54cf2267b3a45d2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1cedee13d25ab118d325f95588c1a084e9317229 6fabca2fc94d33cdf7ec102058983b086293395f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.18","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.4.301 5.4.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.246 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.195 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.156 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.112 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.53 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.17.3 6.17.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18 * original_commit_for_fix","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.6 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.6 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","version":"affected V3.1.6 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","version":"affected V3.1.6 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.6 * custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"40078","cve":"CVE-2025-40078","epss":"0.001970000","percentile":"0.095870000","score_date":"2026-07-14","updated_at":"2026-07-15 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.6","versionType":"custom"}]}],"providerMetadata":{"dateUpdated":"2026-07-14T12:43:18.234Z","orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP"},"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"}],"x_adpType":"supplier"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"de44cdc50d2dce8718cb57deddf9cf1be9a7759f","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"76e04bbb4296fb6eac084dbfc27e02ccc744db3e","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"4f00858cd9bbbdf67159e28b85a8ca9e77c83622","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"cdeafacb4f9ff261a96baef519e29480fd7b1019","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"fe9d33f0470350558cb08cecb54cf2267b3a45d2","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"},{"lessThan":"6fabca2fc94d33cdf7ec102058983b086293395f","status":"affected","version":"1cedee13d25ab118d325f95588c1a084e9317229","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.18"},{"lessThan":"4.18","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.4.*","status":"unaffected","version":"5.4.301","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.246","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.195","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.156","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.112","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.53","versionType":"semver"},{"lessThanOrEqual":"6.17.*","status":"unaffected","version":"6.17.3","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"6.18","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.301","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.246","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.195","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.156","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.112","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.53","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.17.3","versionStartIncluding":"4.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18","versionStartIncluding":"4.18","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n    0: r0 = 0\n    1: r2 = *(u32 *)(r1 +60)\n    2: exit\n\nwhich triggers:\n\n    verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn't rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn't find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch."}],"providerMetadata":{"dateUpdated":"2026-05-11T21:42:04.928Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/de44cdc50d2dce8718cb57deddf9cf1be9a7759f"},{"url":"https://git.kernel.org/stable/c/76e04bbb4296fb6eac084dbfc27e02ccc744db3e"},{"url":"https://git.kernel.org/stable/c/6d8b1a21fd5c34622b0c3893c61e4a38d8ba53ec"},{"url":"https://git.kernel.org/stable/c/4f00858cd9bbbdf67159e28b85a8ca9e77c83622"},{"url":"https://git.kernel.org/stable/c/cdeafacb4f9ff261a96baef519e29480fd7b1019"},{"url":"https://git.kernel.org/stable/c/fe9d33f0470350558cb08cecb54cf2267b3a45d2"},{"url":"https://git.kernel.org/stable/c/ad8b4fe5617e3c85fc23267f02500c4f3bf0ff69"},{"url":"https://git.kernel.org/stable/c/6fabca2fc94d33cdf7ec102058983b086293395f"}],"title":"bpf: Explicitly check accesses to bpf_sock_addr","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2025-40078","datePublished":"2025-10-28T11:48:43.548Z","dateReserved":"2025-04-16T07:20:57.160Z","dateUpdated":"2026-07-14T12:43:18.234Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-10-28 12:15:42","lastModifiedDate":"2026-07-14 13:17:52","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"40078","Ordinal":"1","Title":"bpf: Explicitly check accesses to bpf_sock_addr","CVE":"CVE-2025-40078","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"40078","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Explicitly check accesses to bpf_sock_addr\n\nSyzkaller found a kernel warning on the following sock_addr program:\n\n    0: r0 = 0\n    1: r2 = *(u32 *)(r1 +60)\n    2: exit\n\nwhich triggers:\n\n    verifier bug: error during ctx access conversion (0)\n\nThis is happening because offset 60 in bpf_sock_addr corresponds to an\nimplicit padding of 4 bytes, right after msg_src_ip4. Access to this\npadding isn't rejected in sock_addr_is_valid_access and it thus later\nfails to convert the access.\n\nThis patch fixes it by explicitly checking the various fields of\nbpf_sock_addr in sock_addr_is_valid_access.\n\nI checked the other ctx structures and is_valid_access functions and\ndidn't find any other similar cases. Other cases of (properly handled)\npadding are covered in new tests in a subsequent patch.","Type":"Description","Title":"bpf: Explicitly check accesses to bpf_sock_addr"}]}}}