PT-2025-20354 · Linux+3 · Linux Kernel+3
Published
2025-04-22
·
Updated
2026-03-13
·
CVE-2025-37825
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been identified in the Linux kernel, specifically in the nvmet component. The issue arises when attempting to enable a port without a configured transport, causing an out-of-bounds access in the
nvmet enable port() function. This occurs because NVMF TRTYPE MAX (255) is used to query the transports array. The problem can be avoided by checking for NVMF TRTYPE MAX before proceeding.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Ubuntu