be2net: pass wrb_params in case of OS2BMC
Summary
| CVE | CVE-2025-40264 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-04 16:16:20 UTC |
| Updated | 2026-06-02 14:16:32 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site. This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit(). |
Risk And Classification
EPSS: 0.000890000 probability, percentile 0.253220000 (date 2026-06-08)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 f499dfa5c98e92e72dd454eb95a1000a448f3405 git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 630360c6724e27f1aa494ba3fffe1e38c4205284 git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 012ee5882b1830db469194466a210768ed207388 git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 ce0a3699244aca3acb659f143c9cb1327b210f89 git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 1ecd86ec6efddb59a10c927e8e679f183bb9113e git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d git | Not specified |
| CNA | Linux | Linux | affected 760c295e0e8d982917d004c9095cff61c0cbd803 7d277a7a58578dd62fd546ddaef459ec24ccae36 git | Not specified |
| CNA | Linux | Linux | affected 4.2 | Not specified |
| CNA | Linux | Linux | unaffected 4.2 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.302 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.247 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.197 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.159 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.118 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.60 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.10 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
| ADP | Siemens | RUGGEDCOM RST2428P | affected V4.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/630360c6724e27f1aa494ba3fffe1e38c4205284 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/012ee5882b1830db469194466a210768ed207388 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f499dfa5c98e92e72dd454eb95a1000a448f3405 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1ecd86ec6efddb59a10c927e8e679f183bb9113e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| cert-portal.siemens.com/productcert/html/ssa-253495.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ce0a3699244aca3acb659f143c9cb1327b210f89 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7d277a7a58578dd62fd546ddaef459ec24ccae36 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4c4741f6e7f2fa4e1486cb61e1c15b9236ec134d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.