PT-2025-40249 · Spdk · Spdk

Joel Cunningham

·

Published

2025-10-01

·

Updated

2025-11-14

·

CVE-2025-57275

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Storage Performance Development Kit (SPDK) version 25.05
Description The Storage Performance Development Kit (SPDK) version 25.05 contains a buffer overflow in the NVMe-oF target component, specifically within lib/nvmf.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-57275
GHSA-5M5W-W2H2-FQGQ
OESA-2025-2523
OESA-2025-2524
OESA-2025-2525
OESA-2025-2692
OESA-2025-2693

Affected Products

Spdk