CVE-2025-40192
BaseFortify
Publication date: 2025-11-12
Last updated on: 2025-11-14
Assigner: kernel.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is in the Linux kernel's IPMI driver. A patch intended to fix message stack handling when IPMI is disconnected was reverted because it contained a subtle bug. This bug can cause the IPMI driver to enter an infinite loop if the Baseboard Management Controller (BMC) misbehaves in a specific way. Some BMCs have been reported to misbehave like this, leading to the issue.
How can this vulnerability impact me? :
If the BMC misbehaves as described, the IPMI driver in the Linux kernel can enter an infinite loop. This could potentially lead to system instability or resource exhaustion, affecting system availability and performance.