Home

Description

In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.  This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().

PUBLISHED Reserved 2025-04-16 | Published 2025-12-04 | Updated 2025-12-04 | Assigner Linux

Product status

Default status
unaffected

760c295e0e8d982917d004c9095cff61c0cbd803 (git) before 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe
affected

760c295e0e8d982917d004c9095cff61c0cbd803 (git) before ce0a3699244aca3acb659f143c9cb1327b210f89
affected

760c295e0e8d982917d004c9095cff61c0cbd803 (git) before 1ecd86ec6efddb59a10c927e8e679f183bb9113e
affected

760c295e0e8d982917d004c9095cff61c0cbd803 (git) before 4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d
affected

760c295e0e8d982917d004c9095cff61c0cbd803 (git) before 7d277a7a58578dd62fd546ddaef459ec24ccae36
affected

Default status
affected

4.2
affected

Any version before 4.2
unaffected

5.4.302 (semver)
unaffected

6.6.118 (semver)
unaffected

6.12.60 (semver)
unaffected

6.17.10 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe

git.kernel.org/...c/ce0a3699244aca3acb659f143c9cb1327b210f89

git.kernel.org/...c/1ecd86ec6efddb59a10c927e8e679f183bb9113e

git.kernel.org/...c/4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d

git.kernel.org/...c/7d277a7a58578dd62fd546ddaef459ec24ccae36

cve.org (CVE-2025-40264)

nvd.nist.gov (CVE-2025-40264)