In the Linux kernel, the following vulnerability has been resolved:
ionic: catch failure from devlink_alloc
Add a check for NULL on the alloc return. If devlink_alloc() fails and we try to use devlink_priv() on the NULL return, the kernel gets very unhappy and panics. With this fix, the driver load will still fail, but at least it won't panic the kernel.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 3, 2025 | Oct 3, 2025 |
| Redhat_linux | — | No solution existsUpgrade kernelUpgrade kernel-rt | Nov 14, 2025 | Oct 1, 2025 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-nvidia-tegra-5.15Upgrade linux-raspiUpgrade linux-nvidia-tegraUpgrade linux-lowlatency-hwe-5.15Upgrade linux-bluefieldUpgrade linuxUpgrade linux-aws-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-kvmUpgrade linux-xilinx-zynqmpUpgrade linux-intel-iotg-5.15Upgrade linux-nvidiaUpgrade linux-oracle-5.15Upgrade linux-lowlatencyUpgrade linux-ibmUpgrade linux-realtimeUpgrade linux-riscv-5.15Upgrade linux-gcp-5.15Upgrade linux-azureUpgrade linux-ibm-5.15Upgrade linux-gkeUpgrade linux-gcpUpgrade linux-intel-iotgUpgrade linux-oracleUpgrade linux-nvidia-tegra-igxUpgrade linux-gkeopUpgrade linux-hwe-5.15Upgrade linux-azure-5.15 | Oct 10, 2025 | Oct 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub