PT-2025-46646 · Linux+2 · Linux Kernel+2
Published
2025-10-03
·
Updated
2026-05-07
·
CVE-2025-40171
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel where multiple asynchronous commands can be in flight from the
nvmet fc send ls req function, potentially leading to a leaked tgtport reference. The issue arises because only one put work item is queued at a time, and the current code does not properly manage resource cleanup when multiple commands are active. Moving the work item to the nvmet fc ls req op struct, which already tracks related resources, resolves this.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu