In the Linux kernel, the following vulnerability has been resolved:
iw_cxgb4: Fix potential NULL dereference in c4iw_fill_res_cm_id_entry()
This condition needs to match the previous "if (epcp->state == LISTEN) {" exactly to avoid a NULL dereference of either "listen_ep" or "ep". The problem is that "epcp" has been re-assigned so just testing "if (epcp->state == LISTEN) {" a second time is not sufficient.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 3, 2025 | Oct 3, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-perfUpgrade kernelUpgrade kernel-abi-stablelistsUpgrade kernel-toolsUpgrade bpftoolUpgrade kernel-tools-libs | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade kernel-abi-stablelistsUpgrade kernelUpgrade kernel-tools-libsUpgrade bpftoolUpgrade kernel-toolsUpgrade python3-perf | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-tools-libsUpgrade kernel-toolsUpgrade bpftoolUpgrade python3-perfUpgrade kernel-abi-stablelistsUpgrade kernel | Feb 3, 2026 | Feb 2, 2026 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | Nov 14, 2025 | Oct 1, 2025 |
| Ubuntu | — | Upgrade linux-gcp-5.15Upgrade linux-nvidia-tegraUpgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-aws-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeUpgrade linux-nvidia-tegra-5.15Upgrade linux-realtimeUpgrade linux-lowlatencyUpgrade linux-bluefieldUpgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-kvmUpgrade linux-raspiUpgrade linux-oracleUpgrade linux-gcpUpgrade linux-gkeopUpgrade linux-riscv-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-intel-iotgUpgrade linux-awsUpgrade linuxUpgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-azure-5.15 | Oct 10, 2025 | Oct 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub