CVE-2025-39812: sctp: initialize more fields in sctp_v6_from_sk()

Published Sep 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

sctp: initialize more fields in sctpv6fromsk()

syzbot found that sin6scopeid was not properly initialized, leading to undefined behavior.

Clear sin6scopeid and sin6flowinfo.

BUG: KMSAN: uninit-value in sctpv6cmpaddr+0x887/0x8c0 net/sctp/ipv6.c:649 sctpv6cmpaddr+0x887/0x8c0 net/sctp/ipv6.c:649 sctpinet6cmpaddr+0x4f2/0x510 net/sctp/ipv6.c:983 sctpbindaddrconflict+0x22a/0x3b0 net/sctp/bindaddr.c:390 sctpgetportlocal+0x21eb/0x2440 net/sctp/socket.c:8452 sctpgetport net/sctp/socket.c:8523 [inline] sctplistenstart net/sctp/socket.c:8567 [inline] sctpinetlisten+0x710/0xfd0 net/sctp/socket.c:8636 syslistensocket net/socket.c:1912 [inline] syslisten net/socket.c:1927 [inline] dosyslisten net/socket.c:1932 [inline] sesyslisten net/socket.c:1930 [inline] x64syslisten+0x343/0x4c0 net/socket.c:1930 x64syscall+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls64.h:51 dosyscallx64 arch/x86/entry/syscall64.c:63 [inline] dosyscall64+0xd9/0x210 arch/x86/entry/syscall64.c:94 entrySYSCALL64afterhwframe+0x77/0x7f

Local variable addr.i.i created at: sctpgetport net/sctp/socket.c:8515 [inline] sctplistenstart net/sctp/socket.c:8567 [inline] sctpinetlisten+0x650/0xfd0 net/sctp/socket.c:8636 syslistensocket net/socket.c:1912 [inline] syslisten net/socket.c:1927 [inline] dosyslisten net/socket.c:1932 [inline] sesyslisten net/socket.c:1930 [inline] x64syslisten+0x343/0x4c0 net/socket.c:1930

Affected Software

19 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.96.2-2
Linux Linux kernel>=2.6.12.1<5.4.298
Linux Linux kernel>=5.5<5.10.242
Linux Linux kernel>=5.11<5.15.191
Linux Linux kernel>=5.16<6.1.150
Linux Linux kernel>=6.2<6.6.104
Linux Linux kernel>=6.7<6.12.45
Linux Linux kernel>=6.13<6.16.5
Linux Linux kernel=2.6.12
Linux Linux kernel=2.6.12-rc2
Linux Linux kernel=2.6.12-rc3
Linux Linux kernel=2.6.12-rc4
Linux Linux kernel=2.6.12-rc5
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3
Debian Debian Linux=11.0
Microsoft cbl2 kernel 5.15.186.1-1

Event History

Sep 16, 2025
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 20, 2025
Data Sourced
via Microsoft·01:08 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity
Updated
via Microsoft·08:08 AM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-39812?

CVE-2025-39812 has been categorized as a moderate severity vulnerability in the Linux kernel.

2

How do I fix CVE-2025-39812?

To fix CVE-2025-39812, ensure that you update your Linux kernel to the patched version that addresses the uninitialized fields.

3

What components are affected by CVE-2025-39812?

CVE-2025-39812 affects the Linux kernel due to improper initialization in the sctp_v6_from_sk() function.

4

What are the consequences of CVE-2025-39812?

CVE-2025-39812 can lead to undefined behavior in the Linux kernel, which may cause system instability.

5

Who is responsible for addressing CVE-2025-39812?

The maintainers of the Linux kernel are responsible for addressing CVE-2025-39812 through timely updates and patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203