PT-2025-11012 · Linux+2 · Linux Kernel+2
Published
2025-03-12
·
Updated
2025-06-16
·
CVE-2025-21850
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.13.0-rc6
Description:
A crash can occur in the Linux kernel when a namespace is disabled due to a null pointer dereference. This issue arises because the namespace percpu counter, which protects pending I/O, is not properly initialized and waited for to drop to zero before disabling the namespace. As a result, I/O pending after the namespace has been disabled can cause a crash. The estimated number of potentially affected devices is not specified.
Recommendations:
For Linux kernel versions prior to 6.13.0-rc6, update to a version that includes the fix for the nvmet namespace disable crash.
As a temporary workaround, consider disabling the
nvme loop execute work function until a patch is available.
Restrict access to the nvmet ns disable function to minimize the risk of exploitation.Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse