CVE-2025-40022
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg") changed some fields from bool to 1-bit bitfields of type u32.
However, some assignments to these fields, specifically 'more' and 'merge', assign values greater than 1. These relied on C's implicit conversion to bool, such that zero becomes false and nonzero becomes true.
With a 1-bit bitfields of type u32 instead, mod 2 of the value is taken instead, resulting in 0 being assigned in some cases when 1 was intended.
Leer descripción completaMostrar menos
Fix this by restoring the bool type.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/316b090c2fee964c307a634fecc7df269664b158
- https://git.kernel.org/stable/c/3a21698ace915a445bce2d0dcfc84b6d2199baf7
- https://git.kernel.org/stable/c/54506c6335690f4ef1b9f154e34f5a604c72c1ed
- https://git.kernel.org/stable/c/8703940bd30b5ad94408d28d7192db2491cd3592
- https://git.kernel.org/stable/c/d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb
- https://git.kernel.org/stable/c/d382d6daf0184490f366562469a5673f65ee2662
- https://git.kernel.org/stable/c/fbe96bd25423e61273d8831e995260b429d850b6
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40022",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0f28c4adbc4a97437874c9b669fd7958a8c6d6ce",
"lessThan": "3a21698ace915a445bce2d0dcfc84b6d2199baf7",
"versionType": "git"
},
{
"status": "affected",
"version": "e4c1ec11132ec466f7362a95f36a506ce4dc08c9",
"lessThan": "d382d6daf0184490f366562469a5673f65ee2662",
"versionType": "git"
},
{
"status": "affected",
"version": "1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8",
"lessThan": "54506c6335690f4ef1b9f154e34f5a604c72c1ed",
"versionType": "git"
},
{
"status": "affected",
"version": "7c4491b5644e3a3708f3dbd7591be0a570135b84",
"lessThan": "8703940bd30b5ad94408d28d7192db2491cd3592",
"versionType": "git"
},
{
"status": "affected",
"version": "9aee87da5572b3a14075f501752e209801160d3d",
"lessThan": "316b090c2fee964c307a634fecc7df269664b158",
"versionType": "git"
},
{
"status": "affected",
"version": "45bcf60fe49b37daab1acee57b27211ad1574042",
"lessThan": "fbe96bd25423e61273d8831e995260b429d850b6",
"versionType": "git"
},
{
"status": "affected",
"version": "1b34cbbf4f011a121ef7b2d7d6e6920a036d5285",
"lessThan": "d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb",
"versionType": "git"
}
],
"programFiles": [
"include/crypto/if_alg.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1.154",
"lessThan": "6.1.155",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.108",
"lessThan": "6.6.109",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.49",
"lessThan": "6.12.50",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.16.9",
"lessThan": "6.16.10",
"versionType": "semver"
}
],
"programFiles": [
"include/crypto/if_alg.h"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.5",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.5",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.5",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.5",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.5",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-10-24T13:15:47.387",
"references": [
{
"url": "https://git.kernel.org/stable/c/316b090c2fee964c307a634fecc7df269664b158",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a21698ace915a445bce2d0dcfc84b6d2199baf7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/54506c6335690f4ef1b9f154e34f5a604c72c1ed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8703940bd30b5ad94408d28d7192db2491cd3592",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d0ca0df179c4b21e2a6c4a4fb637aa8fa14575cb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d382d6daf0184490f366562469a5673f65ee2662",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fbe96bd25423e61273d8831e995260b429d850b6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - Fix incorrect boolean values in af_alg_ctx\n\nCommit 1b34cbbf4f01 (\"crypto: af_alg - Disallow concurrent writes in\naf_alg_sendmsg\") changed some fields from bool to 1-bit bitfields of\ntype u32.\n\nHowever, some assignments to these fields, specifically 'more' and\n'merge', assign values greater than 1. These relied on C's implicit\nconversion to bool, such that zero becomes false and nonzero becomes\ntrue.\n\nWith a 1-bit bitfields of type u32 instead, mod 2 of the value is taken\ninstead, resulting in 0 being assigned in some cases when 1 was intended.\n\nFix this by restoring the bool type."
}
],
"lastModified": "2026-07-14T13:17:52.417",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}