PT-2025-11012 · Linux+2 · Linux Kernel+2

Published

2025-03-12

·

Updated

2025-06-16

·

CVE-2025-21850

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.13.0-rc6
Description: A crash can occur in the Linux kernel when a namespace is disabled due to a null pointer dereference. This issue arises because the namespace percpu counter, which protects pending I/O, is not properly initialized and waited for to drop to zero before disabling the namespace. As a result, I/O pending after the namespace has been disabled can cause a crash. The estimated number of potentially affected devices is not specified.
Recommendations: For Linux kernel versions prior to 6.13.0-rc6, update to a version that includes the fix for the nvmet namespace disable crash. As a temporary workaround, consider disabling the nvme loop execute work function until a patch is available. Restrict access to the nvmet ns disable function to minimize the risk of exploitation.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-21850
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1

Affected Products

Astra Linux
Linux Kernel
Suse