cbcvebase.
CVE-2025-40264
published 2025-12-04

CVE-2025-40264: In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the…

PriorityP423high7.8
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site. This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < f499dfa5c98e92e72dd454eb95a1000a448f3405f499dfa5c98e92e72dd454eb95a1000a448f3405
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 630360c6724e27f1aa494ba3fffe1e38c4205284630360c6724e27f1aa494ba3fffe1e38c4205284
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 012ee5882b1830db469194466a210768ed207388012ee5882b1830db469194466a210768ed207388
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < ce0a3699244aca3acb659f143c9cb1327b210f89ce0a3699244aca3acb659f143c9cb1327b210f89
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 1ecd86ec6efddb59a10c927e8e679f183bb9113e1ecd86ec6efddb59a10c927e8e679f183bb9113e
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d
linuxlinux>= 760c295e0e8d982917d004c9095cff61c0cbd803 < 7d277a7a58578dd62fd546ddaef459ec24ccae367d277a7a58578dd62fd546ddaef459ec24ccae36
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.2.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.106.17.10
linuxlinux_kernel>= 6.2.0 < 6.6.1186.6.118
linuxlinux_kernel>= 6.7.0 < 6.12.606.12.60

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.