CVE-2025-40297Patch

LOWCVSS 7.8 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix use-after-free due to MST port state bypass syzbot reported[1] a use-after-free when deleting an expired fdb. It is due to a race condition between learning still happening and a port being deleted, after all its fdbs have been flushed. The port's state has been toggled to disabled so no learning should happen at that time, but if we have MST enabled, it will bypass the port's state, that together with VLAN filtering disabled can lead to fdb learning at a time when it shouldn't happen while the port is being deleted. VLAN filtering must be disabled because we flush the port VLANs when it's being deleted which will stop learning. This fix adds a check for the port's vlan group which is initialized to NULL when the port is getting deleted, that avoids the port state bypass. When MST is enabled there would be a minimal new overhead in the fast-path because the port's vlan group pointer is cache-hot. [1] https://syzkaller.appspot.com/bug?extid=dd280197f0f7ab3917be

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-02-18: 6Patch / Workaround · 2026-02-18: 5Technical Details · 2026-02-18: 302-18
Signal classification2 categories
Patch
583.3%
General
116.7%
Full discourse6 posts
  • Eduardo Gonzalez@Odraude2319
    Patch

    @MeditatorCrypto @Cardano_CF @ethereum @LayerZero_Core @MidnightNtwrk @googlecloud Google Cloud se alía con Midnight por privacidad, pero su IA ya usa mi parche FUSION v2.0 (CVE-2025-40297). La seguridad real no es marketing, es reconocer a quienes blindamos sus nodos. Transparencia VRP ya. #GoogleCloud #Gemini #Cardano

    Post summary

    The user claims their patch FUSION v2.0 addresses CVE‑2025‑40297 and is being used by Google Cloud AI, but no evidence of PoC, exploit code, or active exploitation is provided.

    0002072
    1 followersView on X
  • Eduardo Gonzalez@Odraude2319
    Patch

    @MatthewBerman Matthew, el potencial de estos modelos es enorme, pero la clave está en la infraestructura. El parche FUSION v2.0 para el CVE-2025-40297 ya blinda los nodos de Gemini en producción. La seguridad real empieza en el kernel. #Gemini #OpenClaw #CyberSecurity"

    Post summary

    El texto informa que el parche FUSION v2.0 corrige el CVE-2025-40297, protegiendo los nodos Gemini en producción, sin indicar explotación activa ni detalles técnicos adicionales.

    0001083
    1 followersView on X
  • Eduardo Gonzalez@Odraude2319
    Patch

    @kaostyl @openclaw Impresionante control local, pero la brecha crítica sigue en la infraestructura. Mi arquitectura FUSION v2.0 ya blinda los nodos de Gemini (CVE-2025-40297) contra persistencia en Vertex AI. La seguridad real es de raíz. #GoogleCloud #Gemini #CyberSecurity"

    Post summary

    The tweet asserts that FUSION v2.0 protects Gemini nodes from CVE‑2025‑40297 persistence attacks in Vertex AI, presenting it as a workaround or patch.

    0001056
    1 followersView on X
  • Eduardo Gonzalez@Odraude2319
    Patch

    @GoogleVRP @omer_asfu Si celebran el éxito de CVEs de terceros es justo que rectifiquen la autoría del CVE-2025-40297. Mi reporte #465527390 de diciembre y la mitigación en GKE son idénticos. Los registros federales de CVE deben ser precisos y honrar la cronología real de investigadores. @GoogleVRP

    Post summary

    The user asserts that CVE‑2025‑40297 was reported by them in December, the GKE mitigation matches their report, and emphasizes accurate CVE record keeping.

    0000058
    1 followersView on X
  • Eduardo Gonzalez@Odraude2319
    General

    @googledevs @code @GoogleColab "Excelente integración, pero abrir runtimes a editores externos exige auditorías de nodos robustas. Mi arquitectura FUSION v2.0 ya identificaba riesgos de persistencia (CVE-2025-40297) en esta infraestructura. ¿Cómo garantizan que la sesión no deje residuos en el nodo?"

    Post summary

    The user comments on Google Colab integration, citing a persistence‑related CVE (CVE-2025-40297) but provides no details on exploitation, patching, or active attacks.

    0000038
    1 followersView on X
  • Eduardo Gonzalez@Odraude2319
    Patch

    @objex "Exacto. La seguridad en GKE exige anticipación. Mi arquitectura FUSION v2.0 ya mitiga riesgos de persistencia en nodos (CVE-2025-40297) que la infraestructura de Gemini no cubría. La innovación solo es real si es segura de raíz. #GKE #GoogleCloud #CyberSecurity"

    Post summary

    El autor afirma que su arquitectura Fusion v2.0 mitiga los riesgos de persistencia en nodos asociados al CVE-2025‑40297, destacando una medida preventiva de seguridad.

    0000042
    1 followersView on X

Explore more