| Name | CVE-2025-38456 | 
| Description | In the Linux kernel, the following vulnerability has been resolved:  ipmi:msghandler: Fix potential memory corruption in ipmi_create_user()  The "intf" list iterator is an invalid pointer if the correct "intf->intf_num" is not found.  Calling atomic_dec(&intf->nr_users) on and invalid pointer will lead to memory corruption.  We don't really need to call atomic_dec() if we haven't called atomic_add_return() so update the if (intf->in_shutdown) path as well. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| References | DLA-4328-1, DSA-5973-1, DSA-5975-1 | 
The table below lists information on source packages.
The information below is based on the following data on fixed versions.