PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40257 Siemens CVE debrief

The Linux kernel's Multipath TCP (mptcp) implementation has a race condition vulnerability that can cause a use-after-free error, potentially leading to a denial-of-service or other unspecified impacts. This issue is addressed in updated Linux kernel versions. The vulnerability affects Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems that utilize Multipath TCP (mptcp) functionality. Those affected should assess their exposure and apply patches or updates to prevent potential denial-of-service or other impacts.

Vendor
Siemens
Product
RUGGEDCOM RST2428P (6GK6242-6PA00)
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-02
Original CVE updated
2026-07-07
Advisory published
2026-06-02
Advisory updated
2026-07-07

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems, particularly those using Multipath TCP (mptcp) functionality, should assess exposure and apply patches or updates to prevent potential denial-of-service or other impacts.

Why it matters

A race condition vulnerability in the Linux kernel's mptcp implementation can allow for a use-after-free error, potentially leading to a denial-of-service or other unspecified impacts. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should assess exposure and apply patches or updates.

  • Denial-of-service due to use-after-free error
  • Potential for unspecified impacts due to lack of detailed information
  • Need for patching or updating affected Linux kernel versions

Technical summary

The Linux kernel's mptcp implementation has a race condition vulnerability that can cause a use-after-free error in the mptcp_pm_del_add_timer function. This issue is addressed in updated Linux kernel versions. The vulnerability is caused by a use-after-free error in the mptcp_pm_del_add_timer function, which can potentially lead to a denial-of-service or other unspecified impacts. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should assess exposure and apply patches or updates.

Defensive priority

Apply patches or updates to affected Linux kernel versions to prevent potential denial-of-service or other impacts.

Recommended defensive actions

  • Apply patches or updates to affected Linux kernel versions
  • Review and update affected systems to prevent potential denial-of-service or other impacts
  • Monitor system logs for suspicious activity related to mptcp
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and associated sources describe a race condition vulnerability in the Linux kernel's mptcp implementation. The issue is caused by a use-after-free error in the mptcp_pm_del_add_timer function. This vulnerability can potentially lead to a denial-of-service or other unspecified impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40257 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40257

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40257 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40257

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2025-40257

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-188-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-253495.json

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-253495.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.