CVE-2025-40350
The Linux kernel’s mlx5e driver incorrectly builds socket buffers when XDP programs change the layout of an xdp_buff, which can lead to kernel warnings or crashes. The issue has been fixed in the kernel source.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux systems using the mlx5e driver (Intel/Mellanox 5/6 network adapters).
Real-world impact
An attacker could send specially crafted packets that trigger the bug, causing the kernel to crash or become unstable, effectively denying service to the host.
Why this severity
The CVSS score of 9.8 reflects a network‑based attack that requires no privileges, no user interaction, and can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the CVE‑2025‑40350 fix.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Dec 16, 2025 · Dec 16, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.