ipmi: Rework user message limit handling
Summary
| CVE | CVE-2025-40202 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-11-12 22:15:47 UTC |
| Updated | 2026-07-30 06:24:17 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit on the number of user messages had a number of issues, improper counting in some cases and a use after free. Restructure how this is all done to handle more in the receive message allocation routine, so all refcouting and user message limit counts are done in that routine. It's a lot cleaner and safer. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001360000 probability, percentile 0.035350000 (date 2026-07-31)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 f63723ca7d7623f9dae1990973cd158671f03c56 git | Not specified |
| CNA | Linux | Linux | affected 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 348121b29594d42d1635648fd3ed31dfa25351d5 git | Not specified |
| CNA | Linux | Linux | affected 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 53d6e403affbf6df2c859a0ea00ccfc1e72090ca git | Not specified |
| CNA | Linux | Linux | affected 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5 git | Not specified |
| CNA | Linux | Linux | affected 8e76741c3d8b20dfa2d6c30fa10ff927cfd93d82 b52da4054ee0bf9ecb44996f2c83236ff50b3812 git | Not specified |
| CNA | Linux | Linux | affected 5.19 | Not specified |
| CNA | Linux | Linux | unaffected 5.19 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.157 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.113 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.54 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.4 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/f63723ca7d7623f9dae1990973cd158671f03c56 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/348121b29594d42d1635648fd3ed31dfa25351d5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/53d6e403affbf6df2c859a0ea00ccfc1e72090ca | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b52da4054ee0bf9ecb44996f2c83236ff50b3812 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.