PT-2025-28867 · Unknown+7 · Fibre Channel Network Interface Card+9

Anubis

·

Published

2025-07-09

·

Updated

2025-11-19

·

CVE-2025-38238

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A flaw exists in the Linux kernel related to the Fibre Channel Network Interface Card (fnic) driver. A crash can occur in the fnic wq cmpl handler function when Fibre Distributed Memory Interface (FDMI) requests from both the Remote Host Bus Adapter (RHBA) and Remote Port Adapter (RPA) time out. This happens because the driver attempts to free the same memory frame twice when resending ABTS (Abort Block Transfer Sequence) commands. The issue was addressed by allocating separate frames for RHBA and RPA requests and modifying the ABTS logic. Testing involved dropping various responses (PLOGI, RHBA, RPA) and combinations thereof, along with ABTS responses, to verify the fix.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10748
CVE-2025-38238
SUSE-SU-2025:02853-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1

Affected Products

Astra Linux
Fdmi
Fibre Channel Network Interface Card
Linuxmint
Linux Kernel
Remote Host Bus Adapter
Remote Port Adapter
Suse
Ubuntu
Fnic