SB20250422151 - Resource management error in Linux kernel nvme target driver
Published: April 22, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-39778)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the nvmet_ctrl_state_show() function in drivers/nvme/target/debugfs.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0cc0efc58d6c741b2868d4af24874d7fec28a575
- https://git.kernel.org/stable/c/107a23185d990e3df6638d9a84c835f963fe30a6
- https://git.kernel.org/stable/c/1adc93a525fdee8e2b311e6d5fd93eb69714ca05
- https://git.kernel.org/stable/c/8fbf37a3577b4d64c150cafde338eee17b2f2ea4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.11