CVE-2025-40252
A critical out-of-bounds read vulnerability existed in the qede driver of the Linux kernel. The issue could let an attacker read memory beyond a fixed-size array, potentially exposing sensitive data. The kernel team has fixed the problem by adding bounds checks.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running affected kernel versions that include the qlogic/qede driver. The vulnerability applies to systems that use this driver in their network stack.
Real-world impact
An attacker could read arbitrary memory, potentially leaking confidential information or compromising system integrity.
Why this severity
The CVSS score of 9.8 reflects the vulnerability’s ability to be exploited remotely with no authentication, no user interaction, and the potential to compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to a version that includes the qede driver patch.
- 02Reboot the system to load the updated kernel.
NVD description
Timeline
- Dec 4, 2025 · Dec 4, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/896f1a2493b59beb2b…
- git.kernel.org/stable/c/917a9d02182ac8b4f2…
- git.kernel.org/stable/c/a778912b4a53587ea0…
- git.kernel.org/stable/c/e441db07f208184e04…
- git.kernel.org/stable/c/ecbb12caf399d7cf36…
- git.kernel.org/stable/c/f0923011c1261b33a2…
- cert-portal.siemens.com/productcert/html/ssa-253495…