目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-40264— Linux kernel 安全漏洞

AI Predicted 4.4 Difficulty: Easy EPSS 0.21% · P12

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

ベンダープロダクトVersion Rangeステータス
LinuxLinux760c295e0e8d982917d004c9095cff61c0cbd803< 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfeaffected
760c295e0e8d982917d004c9095cff61c0cbd803< f499dfa5c98e92e72dd454eb95a1000a448f3405affected
760c295e0e8d982917d004c9095cff61c0cbd803< 630360c6724e27f1aa494ba3fffe1e38c4205284affected
760c295e0e8d982917d004c9095cff61c0cbd803< 012ee5882b1830db469194466a210768ed207388affected
760c295e0e8d982917d004c9095cff61c0cbd803< ce0a3699244aca3acb659f143c9cb1327b210f89affected
760c295e0e8d982917d004c9095cff61c0cbd803< 1ecd86ec6efddb59a10c927e8e679f183bb9113eaffected
760c295e0e8d982917d004c9095cff61c0cbd803< 4c4741f6e7f2fa4e1486cb61e1c15b9236ec134daffected
760c295e0e8d982917d004c9095cff61c0cbd803< 7d277a7a58578dd62fd546ddaef459ec24ccae36affected
… +10 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-40264の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
be2net: pass wrb_params in case of OS2BMC
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.  This may lead to dereferencing a NULL pointer when processing a workaround for specific packet, as commit bc0c3405abbb ("be2net: fix a Tx stall bug caused by a specific ipv6 packet") states. The correct way would be to pass the wrb_params from be_xmit().
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于传递NULL指针,可能导致空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 760c295e0e8d982917d004c9095cff61c0cbd803 ~ 48d59b60dd5d7e4c48c077a2008c9dcd7b59bdfe -
LinuxLinux 4.2 -

II. CVE-2025-40264の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-40264のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-04 · 53 CVEs total

CVE-2025-402619.8 CRITICALnvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
CVE-2025-402589.8 CRITICALmptcp: fix race condition in mptcp_schedule_work()
CVE-2025-402579.8 CRITICALmptcp: fix a race in mptcp_pm_del_add_timer()
CVE-2025-402529.8 CRITICALnet: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
CVE-2025-402538.8 HIGHs390/ctcm: Fix double-kfree
CVE-2025-402668.2 HIGHKVM: arm64: Check the untrusted offset in FF-A memory share
CVE-2025-402447.8 HIGHhfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
CVE-2025-402507.8 HIGHnet/mlx5: Clean up only new IRQ glue on request_irq() failure
CVE-2025-402627.8 HIGHInput: imx_sc_key - fix memory corruption on unload
CVE-2025-402517.8 HIGHdevlink: rate: Unset parent pointer in devl_rate_nodes_destroy
CVE-2025-402487.8 HIGHvsock: Ignore signal/timeout on connect() if already established
CVE-2025-402497.8 HIGHgpio: cdev: make sure the cdev fd is still active before emitting events
CVE-2025-402457.8 HIGHnios2: ensure that memblock.current_limit is set when setting pfn limits
CVE-2025-402147.8 HIGHaf_unix: Initialise scc_index in unix_add_edge().
CVE-2025-402437.8 HIGHhfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
CVE-2025-402417.8 HIGHerofs: fix crafted invalid cases for encoded extents
CVE-2025-402337.8 HIGHocfs2: clear extent cache after moving/defragmenting extents
CVE-2025-402167.8 HIGHio_uring/rsrc: don't rely on user vaddr alignment
CVE-2025-402157.8 HIGHxfrm: delete x->tunnel as we delete x
CVE-2025-402407.5 HIGHsctp: avoid NULL dereference when chunk data buffer is missing

Showing 20 of 53 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-40264へのコメント

まだコメントはありません


コメントを残す