CVE-2025-40264
Last modified
CVE-2025-40264 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site. This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site. This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < f499dfa5c98e92e72dd454eb95a1000a448f3405; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 630360c6724e27f1aa494ba3fffe1e38c4205284; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 012ee5882b1830db469194466a210768ed207388; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < ce0a3699244aca3acb659f143c9cb1327b210f89; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 1ecd86ec6efddb59a10c927e8e679f183bb9113e; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d; >= 760c295e0e8d982917d004c9095cff61c0cbd803, < 7d277a7a58578dd62fd546ddaef459ec24ccae36 |
| Linux | Linux | 4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40264?
How severe is CVE-2025-40264?
How do I fix CVE-2025-40264?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40259In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4026A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-40260In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40261In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2025-40262In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40263In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40265In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40266In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2025-40267In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40268In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40269In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-4027A vulnerability, which was classified as critical, was found…9.8
Are you affected by CVE-2025-40264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
