CVE-2025-39676

Source
https://cve.org/CVERecord?id=CVE-2025-39676
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39676.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39676
Downstream
Related
Published
2025-09-05T17:20:42.270Z
Modified
2026-06-18T03:56:46.294511264Z
Summary
scsi: qla4xxx: Prevent a potential error pointer dereference
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla4xxx: Prevent a potential error pointer dereference

The qla4xxxgetepfwdb() function is supposed to return NULL on error, but qla4xxxep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39676.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
13483730a13bef372894aefcf73760f5c6c297be
Fixed
d0225f41ee70611ca88ccb22c8542ecdfa7faea8
Fixed
ad8a9d38d30c691a77c456e72b78f7932d4f234d
Fixed
325bf7d57c4e2a341e381c5805e454fb69dd78c3
Fixed
46288d12d1c30d08fbeffd05abc079f57a43a2d4
Fixed
f5ad0819f902b4b33591791b92a0350fb3692a6b
Fixed
f1424c830d6ce840341aac33fe99c8ac45447ac1
Fixed
f4bc3cdfe95115191e24592bbfc15f1d4a705a75
Fixed
9dcf111dd3e7ed5fce82bb108e3a3fc001c07225

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39676.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.4.297
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.241
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.190
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.149
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.103
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.44
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39676.json"