PT-2025-17281 · Linux+4 · Linux Kernel+4

Published

2025-03-24

·

Updated

2026-01-26

·

CVE-2025-39778

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.23 Linux kernel versions prior to 6.13.11 Linux kernel versions prior to 6.14.2
Description A potential out-of-bounds stack read issue exists due to the iteration code in nvmet ctrl state show() accessing the csts state names[] array beyond its bounds. This issue is resolved by fixing the iteration to prevent the out-of-bounds access.
Recommendations For Linux kernel versions prior to 6.12.23, update to version 6.12.23 or later. For Linux kernel versions prior to 6.13.11, update to version 6.13.11 or later. For Linux kernel versions prior to 6.14.2, update to version 6.14.2 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11859
CVE-2025-39778
USN-7594-1
USN-7594-2
USN-7594-3
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu