PT-2025-40645 · Linux+6 · Linux Kernel+6

Published

2025-09-14

·

Updated

2026-05-26

·

CVE-2025-39949

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the qed driver related to handling protection override GRC elements. The firmware can return an excessive number of these elements, leading to a buffer overflow when attempting to dump them. This results in a kernel panic, specifically an “unable to handle kernel paging request” error. The issue occurs in both the qede Ethernet driver and the qedf storage driver paths. The vulnerable code includes functions such as qed grc dump addr range, qed protection override dump, qed dbg protection override dump, qed dbg feature, qed dbg all data, qed fw fatal reporter dump, and devlink health do dump. The panic occurs due to writing past the end of the dump buf buffer, located in p hwfn->cdev->dbg features[DBG FEATURE PROTECTION OVERRIDE].
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unchecked Return Value

Weakness Enumeration

Related Identifiers

AZL-68157
AZL-75345
BDU:2026-02671
CVE-2025-39949
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-70A6-5172-D9D7
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2633
OESA-2025-2634
OESA-2025-2635
OESA-2026-1075
OESA-2026-1076
OPENSUSE-SU-2025:20091-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4301-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Qede
Qedf