In the Linux kernel, the following vulnerability has been resolved:
scsi: qla4xxx: Prevent a potential error pointer dereference
The qla4xxxgetepfwdb() function is supposed to return NULL on error, but qla4xxxep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39676.json",
"cna_assigner": "Linux"
}[
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qla4xxx/ql4_os.c",
"function": "qla4xxx_get_ep_fwdb"
},
"id": "CVE-2025-39676-31a599f3",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@325bf7d57c4e2a341e381c5805e454fb69dd78c3",
"digest": {
"function_hash": "225250251075172108322164211905918045207",
"length": 817.0
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"259522486541474340229774040881243431449",
"328852096466943670083815049788764246459",
"73675784507166850613896116884939290019",
"85681359622404988983457684793354193932"
],
"threshold": 0.9
},
"id": "CVE-2025-39676-81c8771d",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@325bf7d57c4e2a341e381c5805e454fb69dd78c3",
"target": {
"file": "drivers/scsi/qla4xxx/ql4_os.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-39676.json"