Use-After-Free Vulnerability in Ocelot Switch by Vendor MSCC
CVE-2025-40003

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 October 2025

What is CVE-2025-40003?

A use-after-free vulnerability exists in the Ocelot switch's delayed work item handling. When the work item is executed during resource deallocation, it can lead to a warning and potential instability in the network system. This issue arises from the improper cancellation of delayed work in certain conditions, allowing for the work item to be queued again after the resource is deallocated. Proper synchronization methods need to be implemented to ensure that delayed work items do not present a risk of being rescheduled after resource destruction.

Affected Version(s)

Linux a556c76adc052c979ef9e80f0cd3fa1379ff4943

Linux 4.18

Linux 4.18

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40003 : Use-After-Free Vulnerability in Ocelot Switch by Vendor MSCC