PT-2025-14308 · Linux+9 · Linux Kernel+9

Published

2025-04-01

·

Updated

2026-05-26

·

CVE-2025-21927

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential memory corruption issue has been identified in the Linux kernel, specifically in the nvme-tcp module. The nvme tcp recv pdu() function does not validate the header length, which can lead to memory corruption when header digests are enabled. If a target sends a packet with an invalid header length, the nvme tcp verify hdgst() function may access memory outside the allocated area, causing memory corruption by overwriting it with the calculated digest.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:7423
ALT-PU-2025-12647
ALT-PU-2025-5786
AZL-59922
AZL-59952
BDU:2025-14104
CVE-2025-21927
ECHO-211C-7C37-EE75
INFSA-2025_4341
INFSA-2025_7423
OESA-2025-1446
OESA-2025-1450
OESA-2025-1727
OESA-2025-1728
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:4339
RHSA-2025:4340
RHSA-2025:4341
RHSA-2025:4469
RHSA-2025:4471
RHSA-2025:4496
RHSA-2025:4497
RHSA-2025:4498
RHSA-2025:4499
RHSA-2025:4509
RHSA-2025:7423
RHSA-2025:7501
RHSA-2025_4341
RHSA-2025_7423
SUSE-SU-2025:01600-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu