CVE-2025-39676
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: qla4xxx: Prevent a potential error pointer dereference The qla4xxx_get_ep_fwdb() function is supposed to return NULL on error, but qla4xxx_ep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 7%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- debian•debian_linux
11.0
- linux•linux
≥ 13483730a13bef372894aefcf73760f5c6c297be, < d0225f41ee70611ca88ccb22c8542ecdfa7faea8 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < ad8a9d38d30c691a77c456e72b78f7932d4f234d | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 325bf7d57c4e2a341e381c5805e454fb69dd78c3 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 46288d12d1c30d08fbeffd05abc079f57a43a2d4 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f5ad0819f902b4b33591791b92a0350fb3692a6b | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f1424c830d6ce840341aac33fe99c8ac45447ac1 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f4bc3cdfe95115191e24592bbfc15f1d4a705a75 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 9dcf111dd3e7ed5fce82bb108e3a3fc001c07225 | 3.2
- linux•linux_kernel
≥ 3.2.1, < 5.4.297 | ≥ 5.5, < 5.10.241 | ≥ 5.11, < 5.15.190 | ≥ 5.16, < 6.1.149 | ≥ 6.2, < 6.6.103 | ≥ 6.7, < 6.12.44 | ≥ 6.13, < 6.16.4 | 3.2 | 3.2:rc7 | 6.17:rc1 | 6.17:rc2
References (11)
- https://git.kernel.org/stable/c/d0225f41ee70611ca88ccb22c8542ecdfa7faea8
- https://git.kernel.org/stable/c/ad8a9d38d30c691a77c456e72b78f7932d4f234d
- https://git.kernel.org/stable/c/325bf7d57c4e2a341e381c5805e454fb69dd78c3
- https://git.kernel.org/stable/c/46288d12d1c30d08fbeffd05abc079f57a43a2d4
- https://git.kernel.org/stable/c/f5ad0819f902b4b33591791b92a0350fb3692a6b
- https://git.kernel.org/stable/c/f1424c830d6ce840341aac33fe99c8ac45447ac1
- https://git.kernel.org/stable/c/f4bc3cdfe95115191e24592bbfc15f1d4a705a75
- https://git.kernel.org/stable/c/9dcf111dd3e7ed5fce82bb108e3a3fc001c07225
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html