cbcvebase.
CVE-2025-40202
published 2025-11-12

CVE-2025-40202: In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit on the number of user messages had a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit on the number of user messages had a number of issues, improper counting in some cases and a use after free. Restructure how this is all done to handle more in the receive message allocation routine, so all refcouting and user message limit counts are done in that routine. It's a lot cleaner and safer.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 < f63723ca7d7623f9dae1990973cd158671f03c56f63723ca7d7623f9dae1990973cd158671f03c56
linuxlinux>= 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 < 348121b29594d42d1635648fd3ed31dfa25351d5348121b29594d42d1635648fd3ed31dfa25351d5
linuxlinux>= 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 < 53d6e403affbf6df2c859a0ea00ccfc1e72090ca53d6e403affbf6df2c859a0ea00ccfc1e72090ca
linuxlinux>= 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 < 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b50ed73be9a2547ffb9b5c1d879ad9bfab73d920b5
linuxlinux>= 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 < b52da4054ee0bf9ecb44996f2c83236ff50b3812b52da4054ee0bf9ecb44996f2c83236ff50b3812
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 5.19.0 < 6.1.1576.1.157
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.2.0 < 6.6.1136.6.113
linuxlinux_kernel>= 6.7.0 < 6.12.546.12.54
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.