cbcvebase.
CVE-2025-71137
published 2026-01-14

CVE-2025-71137: In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" This patch ensures that the RX ring…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.3th percentile
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" This patch ensures that the RX ring size (rx_pending) is not set below the permitted length. This avoids UBSAN shift-out-of-bounds errors when users passes small or zero ring sizes via ethtool -G.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < 5d8dfa3abb9a845302e021cf9c92d941abbc011a5d8dfa3abb9a845302e021cf9c92d941abbc011a
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < 4cc4cfe4d23c883120b6f3d41145edbaa281f2ab4cc4cfe4d23c883120b6f3d41145edbaa281f2ab
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < 658caf3b8aad65f8b8e102670ca4f68c7030f655658caf3b8aad65f8b8e102670ca4f68c7030f655
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < b23a2e15589466a027c9baa3fb5813c9f6a6c6dcb23a2e15589466a027c9baa3fb5813c9f6a6c6dc
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < aa743b0d98448282b2cb37356db8db2a48524624aa743b0d98448282b2cb37356db8db2a48524624
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < 442848e457f5a9f71a4e7e14d24d73dae278ebe3442848e457f5a9f71a4e7e14d24d73dae278ebe3
linuxlinux>= d45d8979840d9c9ac93d3fe8cfc8e794b7228445 < 85f4b0c650d9f9db10bda8d3acfa1af83bf78cf785f4b0c650d9f9db10bda8d3acfa1af83bf78cf7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.6.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.6.1 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.