CVE-2025-39676

MEDIUM

Linux Kernel - NULL Pointer Dereference in qla4xxx_get_ep_fwdb

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla4xxx: Prevent a potential error pointer dereference The qla4xxx_get_ep_fwdb() function is supposed to return NULL on error, but qla4xxx_ep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (29)
debian/debian_linux 11.0
linux/Kernel 3.2.0 - 5.4.297linux
linux/Kernel 5.11.0 - 5.15.190linux
linux/Kernel 5.16.0 - 6.1.149linux
linux/Kernel 5.5.0 - 5.10.241linux
linux/Kernel 6.13.0 - 6.16.4linux
linux/Kernel 6.2.0 - 6.6.103linux
linux/Kernel 6.7.0 - 6.12.44linux
Linux/Linux < 3.2
Linux/Linux 13483730a13bef372894aefcf73760f5c6c297be - 325bf7d57c4e2a341e381c5805e454fb69dd78c3
... and 19 more
Published Sep 05, 2025
Tracked Since Feb 18, 2026