In the Linux kernel, the following vulnerability has been resolved:
ipmi: Rework user message limit handling
The limit on the number of user messages had a number of issues, improper counting in some cases and a use after free.
Restructure how this is all done to handle more in the receive message allocation routine, so all refcouting and user message limit counts are done in that routine. It's a lot cleaner and safer.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux-6.1Upgrade linux | Nov 14, 2025 | Nov 14, 2025 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1029-xilinxUpgrade linux-image-azureUpgrade linux-image-azure-fipsUpgrade linux-image-xilinx-6.8Upgrade linux-image-xilinx-zynqmpUpgrade linux-image-azure-fips-6.8Upgrade linux-image-azure-lts-24.04Upgrade linux-image-xilinxUpgrade linux-image-6.8.0-1052-azure-fipsUpgrade linux-image-azure-6.8Upgrade linux-image-6.8.0-1051-azure | Mar 24, 2026 | Nov 12, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Nov 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub