CVE-2025-40202
Published Nov 12, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit on the number of user messages had a number of issues, improper counting in some cases and a use after free. Restructure how this is all done to handle more in the receive message allocation routine, so all refcouting and user message limit counts are done in that routine. It's a lot cleaner and safer.
Is your site exposed to CVE-2025-40202?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5
https://git.kernel.org/stable/c/348121b29594d42d1635648fd3ed31dfa25351d5
https://git.kernel.org/stable/c/53d6e403affbf6df2c859a0ea00ccfc1e72090ca
https://git.kernel.org/stable/c/b52da4054ee0bf9ecb44996f2c83236ff50b3812
https://git.kernel.org/stable/c/f63723ca7d7623f9dae1990973cd158671f03c56
Frequently Asked Questions
What is CVE-2025-40202? +
In the Linux kernel, the following vulnerability has been resolved:
ipmi: Rework user message limit handling
The limit on the number of user messages had a number of issues,
improper counting in some cases and a use after free.
Restructure how this is all done to handle more in the receive message
allocation routine, so all refcouting and user message limit counts
are done in that routine. It's a lot cleaner and safer.
How do I check if I'm vulnerable to CVE-2025-40202? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.