CVE-2025-40252 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede_tpa_end()', iterate over 'cqe->len_list[]' using only a zero-length terminator as the stopping condition. If the terminator was missing or malformed, the loop could run past the end of the fixed-size array. Add an explicit bound check using ARRAY_SIZE() in both loops to prevent a potential out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.
A potential out-of-bounds read vulnerability has been identified in the Linux kernel's QLogic QEDE network driver. This issue arises in the 'qede_tpa_cont()' and 'qede_tpa_end()' functions, where loops iterate over the 'cqe->len_list[]' array using only a zero-length terminator as the stopping condition. If the terminator is missing or malformed, the loop may exceed the bounds of the fixed-size array, leading to undefined behavior. The vulnerability has been addressed by adding an explicit boundary check using ARRAY_SIZE() in both functions, preventing the out-of-bounds access.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. The specific commit addressing this issue is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-253495.html | siemens-SADP | |
| https://git.kernel.org/stable/c/896f1a2493b59beb2b5ccdf990503dbb16cb2256 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/917a9d02182ac8b4f25eb47dc02f3ec679608c24 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/a778912b4a53587ea07d85526d152f85d109cbfe | kernel.org | |
| https://git.kernel.org/stable/c/e441db07f208184e0466abf44b389a81d70c340e | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/ecbb12caf399d7cf364b7553ed5aebeaa2f255bc | kernel.org | |
| https://git.kernel.org/stable/c/f0923011c1261b33a2ac1de349256d39cb750dd0 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
| QLogic Qede | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 2, 2026 | CVE Modified | siemens-SADP |
| Dec 6, 2025 | CVE Modified | kernel.org |
| Dec 4, 2025 | New CVE Received | kernel.org |
Volerion