Upstream information

CVE-2025-40202 at MITRE

Description

In the Linux kernel, the following vulnerability has been resolved:

ipmi: Rework user message limit handling

The limit on the number of user messages had a number of issues,
improper counting in some cases and a use after free.

Restructure how this is all done to handle more in the receive message
allocation routine, so all refcouting and user message limit counts
are done in that routine. It's a lot cleaner and safer.

SUSE information

Overall state of this security issue: New

This issue is currently rated as having not set severity.

SUSE Bugzilla entry: 1253451 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Thu Nov 13 00:04:04 2025
CVE page last modified: Thu Nov 13 17:28:00 2025