CVE-2025-40176 Affecting rv package, versions <0:6.12.0-124.27.1.el10_1


Severity

Recommended
high

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.03% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE10-RV-14921525
  • published13 Jan 2026
  • disclosed12 Nov 2025

Introduced: 12 Nov 2025

CVE-2025-40176  (opens in a new tab)

How to fix?

Upgrade Oracle:10 rv to version 0:6.12.0-124.27.1.el10_1 or higher.
This issue was patched in ELSA-2026-0453.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rv package and not the rv package as distributed by Oracle. See How to fix? for Oracle:10 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

tls: wait for pending async decryptions if tls_strp_msg_hold fails

Async decryption calls tls_strp_msg_hold to create a clone of the input skb to hold references to the memory it uses. If we fail to allocate that clone, proceeding with async decryption can lead to various issues (UAF on the skb, writing into userspace memory after the recv() call has returned).

In this case, wait for all pending decryption requests.

CVSS Base Scores

version 3.1