CVE-2025-39676

Advisory lineage Upstream: 0 Downstream: 48
Modified
Published: 05 Sept 2025, 17:20
Last modified:12 May 2026, 12:06

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Sept 2025, 17:20
Published
Vulnerability first disclosed
12 May 2026, 12:06
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla4xxx: Prevent a potential error pointer dereference The qla4xxx_get_ep_fwdb() function is supposed to return NULL on error, but qla4xxx_ep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 7%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • debiandebian_linux

    11.0

  • linuxlinux

    ≥ 13483730a13bef372894aefcf73760f5c6c297be, < d0225f41ee70611ca88ccb22c8542ecdfa7faea8 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < ad8a9d38d30c691a77c456e72b78f7932d4f234d | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 325bf7d57c4e2a341e381c5805e454fb69dd78c3 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 46288d12d1c30d08fbeffd05abc079f57a43a2d4 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f5ad0819f902b4b33591791b92a0350fb3692a6b | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f1424c830d6ce840341aac33fe99c8ac45447ac1 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < f4bc3cdfe95115191e24592bbfc15f1d4a705a75 | ≥ 13483730a13bef372894aefcf73760f5c6c297be, < 9dcf111dd3e7ed5fce82bb108e3a3fc001c07225 | 3.2

  • linuxlinux_kernel

    ≥ 3.2.1, < 5.4.297 | ≥ 5.5, < 5.10.241 | ≥ 5.11, < 5.15.190 | ≥ 5.16, < 6.1.149 | ≥ 6.2, < 6.6.103 | ≥ 6.7, < 6.12.44 | ≥ 6.13, < 6.16.4 | 3.2 | 3.2:rc7 | 6.17:rc1 | 6.17:rc2

References (11)