CVE-2025-40129Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix null pointer dereference on zero-length checksum In xdr_stream_decode_opaque_auth(), zero-length checksum.len causes checksum.data to be set to NULL. This triggers a NPD when accessing checksum.data in gss_krb5_verify_mic_v2(). This patch ensures that the value of checksum.len is not less than XDR_UNIT.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Peaked 1d ago at 3 mentions (2026-02-13); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-13: 3Mentions · 2026-02-16: 1Patch / Workaround · 2026-02-13: 3Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-13: 3Technical Details · 2026-02-16: 102-1302-16
Signal classification1 categories
Patch
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-133
Patch3
2026-02-161
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Critical #SUSE Linux Kernel RT Update! 🚨 SUSE-SU-2026:0490-1 patches 3 high-severity CVEs (including a nasty SUNRPC flaw CVE-2025-40129 with CVSS 8.7). Read more: 👉 https://tinyurl.com/bw3c8s9x #Security https://t.co/4v5IXb9p6b

    Post summary

    SUSE’s SUSE-SU-2026:0490-1 patch update addresses three high‑severity CVEs, including the SUNRPC flaw CVE-2025-40129 with a CVSS score of 8.7.

    0001064
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    New #SUSE kernel live patches just dropped for February. This one's significant because it includes a fix for a null pointer deref in SUNRPC (CVE-2025-40129) that could be triggered remotely on NFS servers. Read more: 👉 https://tinyurl.com/mvj4886s #Security https://t.co/5VZTtLsfkE

    Post summary

    SUSE released kernel live patches that fix CVE‑2025‑40129, a remote‑triggerable null pointer dereference in SUNRPC on NFS servers.

    0000058
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE Kernel RT Live Patch 2 (SUSE-SU-2026:0489-1) 🚨 Four critical CVEs fixed including CVE-2025-38352 (Race Condition) & CVE-2025-40129 (Unauthenticated NFS DoS). Read more: 👉 https://tinyurl.com/33fw5wb5 #Security https://t.co/sSHazKwSqa

    Post summary

    SUSE announces that its Kernel RT Live Patch 2 resolves four critical CVEs, notably a race condition and an unauthenticated NFS Denial‑of‑Service.

    0000055
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Linux Kernel update from @SUSE! 🛡️ SUSE-SU-2026:0491-1 patches CVE-2025-40129 (remote DoS in SUNRPC) & CVE-2025-40186 (local privilege escalation in TCP). Read more: 👉 https://tinyurl.com/yvh83tt6 #Security https://t.co/x5Dgj0rMCy

    Post summary

    SUSE releases the SUSE-SU-2026:0491-1 patch addressing two Linux Kernel CVEs, detailing the vulnerabilities as remote DoS in SUNRPC and local privilege escalation in TCP.

    0000052
    1.3K followersView on X

Explore more