CVE-2025-40173

Public on 2025-11-12
Modified on 2025-11-13
Description
In the Linux kernel, the following vulnerability has been resolved:

net/ip6_tunnel: Prevent perpetual tunnel growth
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Kernel-5.10 Extra kernel 2026-02-19 ALAS2KERNEL-5.10-2026-112 Fixed
Amazon Linux 2 - Core kernel 2026-02-05 ALAS2-2026-3161 Fixed
Amazon Linux 2 - Kernel-5.15 Extra kernel 2025-12-08 ALAS2KERNEL-5.15-2025-094 Fixed
Amazon Linux 2 - Kernel-5.4 Extra kernel 2025-11-10 ALAS2KERNEL-5.4-2025-114 Fixed
Amazon Linux 2023 kernel 2025-12-08 ALAS2023-2025-1297 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.245-241.976 2026-01-05 ALAS2LIVEPATCH-2025-283 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.155-176.282 2026-01-07 ALAS2023LIVEPATCH-2025-111 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.156-177.286 2026-01-07 ALAS2023LIVEPATCH-2025-112 Fixed
Amazon Linux 2023 kernel-livepatch-6.12.53-69.119 2026-01-07 ALAS2023LIVEPATCH-2025-110 Fixed
Amazon Linux 2023 kernel6.12 2025-12-08 ALAS2023-2025-1316 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H