{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-39702","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.115Z","datePublished":"2025-09-05T17:21:08.674Z","dateUpdated":"2026-08-05T12:04:40.981Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:04:40.981Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: Fix MAC comparison to be constant-time\n\nTo prevent timing attacks, MACs need to be compared in constant time.\nUse the appropriate helper function for this."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable comparison sits in the IPv6 Segment Routing Header receive path (`ipv6_srh_rcv()` and the seg6_local behaviors), processing routed IPv6 packets from any remote source. SRv6 packets are not link-local, so an attacker anywhere on the network can drive the oracle.\nAC:L - The attacker controls both sides of the measurement — the candidate MAC bytes and an unlimited, self-paced stream of probe packets — so the byte-at-a-time `memcmp` leak can be amplified by repetition and statistical averaging, including jitter-immune concurrent-probe techniques. No condition depends on state the attacker cannot influence.\nPR:N - The HMAC validation is itself the authentication gate for the SR domain; nothing on the path from packet receive to `seg6_hmac_validate_skb()` checks any credential or capability. The attacker is an unauthenticated off-path/off-domain sender.\nUI:N - Exploitation requires only sending crafted SRv6 packets to the target; no victim action is involved.\nS:U - The forged authentication is consumed and acted upon within the same kernel networking authority that performs the check; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Forging the SRH MAC bypasses the SR-domain trust boundary, letting the attacker source-route packets to otherwise unreachable internal nodes and, via End.DT4/DT6/DX behaviors, into isolated tenant VRFs and L2 domains, with the return path steerable back to the attacker. The timing oracle additionally recovers secret-key-derived MAC values.\nI:H - A recovered MAC makes the kernel accept attacker-crafted segment lists as authentic, allowing arbitrary rewriting of forwarding paths and injection of spoofed traffic into tenant networks and internal L2 bridges — a complete authentication bypass of the SRv6 integrity mechanism.\nA:H - Forged segment lists can be built to loop packets repeatedly between SR nodes and to blackhole or misdirect legitimate traffic, disrupting forwarding for the node and the SR domain it serves."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/seg6_hmac.c"],"versions":[{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"ff55a452d56490047f5233cc48c5d933f8586884","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"3b348c9c8d2ca2c67559ffd0e258ae7e1107d4f0","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"86b6d34717fe0570afce07ee79b8eeb40341f831","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"3ddd55cf19ed6cc62def5e3af10c2a9df1b861c3","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"b3967c493799e63f648e9c7b6cb063aa2aed04e7","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"f7878d47560d61e3f370aca3cebb8f42a55b990a","status":"affected","versionType":"git"},{"version":"bf355b8d2c30a289232042cacc1cfaea4923936c","lessThan":"a458b2902115b26a25d67393b12ddd57d1216aaa","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/seg6_hmac.c"],"versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","status":"unaffected","versionType":"semver"},{"version":"5.10.249","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.190","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.149","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.103","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.44","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.16.4","lessThanOrEqual":"6.16.*","status":"unaffected","versionType":"semver"},{"version":"6.17","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.10.249"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.15.190"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.1.149"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.6.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.12.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.16.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.17"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ff55a452d56490047f5233cc48c5d933f8586884"},{"url":"https://git.kernel.org/stable/c/3b348c9c8d2ca2c67559ffd0e258ae7e1107d4f0"},{"url":"https://git.kernel.org/stable/c/86b6d34717fe0570afce07ee79b8eeb40341f831"},{"url":"https://git.kernel.org/stable/c/3ddd55cf19ed6cc62def5e3af10c2a9df1b861c3"},{"url":"https://git.kernel.org/stable/c/b3967c493799e63f648e9c7b6cb063aa2aed04e7"},{"url":"https://git.kernel.org/stable/c/f7878d47560d61e3f370aca3cebb8f42a55b990a"},{"url":"https://git.kernel.org/stable/c/a458b2902115b26a25d67393b12ddd57d1216aaa"}],"title":"ipv6: sr: Fix MAC comparison to be constant-time","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T17:42:30.669Z"}},{"x_adpType":"supplier","providerMetadata":{"orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP","dateUpdated":"2026-05-12T12:06:24.521Z"},"affected":[{"vendor":"Siemens","product":"SIMATIC CN 4100","versions":[{"status":"affected","version":"0","lessThan":"V5.0","versionType":"custom"}],"defaultStatus":"unknown"}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-032379.html"}]}]}}