« Volver al listado

CVE-2025-40171

Estado: AplazadaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

nvmet-fc: move lsop put work to nvmet_fc_ls_req_op

It’s possible for more than one async command to be in flight from __nvmet_fc_send_ls_req. For each command, a tgtport reference is taken.

In the current code, only one put work item is queued at a time, which results in a leaked reference.

To fix this, move the work item to the nvmet_fc_ls_req_op struct, which already tracks all resources related to the command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40171",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5e0bc09a52b6169ce90f7ac6e195791adb16cec4",
              "lessThan": "11269c08013f4ee8b8f5edc6c56700acb34092d0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9e6987f8937a7bd7516aa52f25cb7e12c0c92ee8",
              "lessThan": "a28112cc55013cd8cbd5d36b5115a5b851151bd9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eaf0971fdabf2a93c1429dc6bedf3bbe85dffa30",
              "lessThan": "060ecc81240ef9d60d9485a3a5eb55a0d6e7a25c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "710c69dbaccdac312e32931abcb8499c1525d397",
              "lessThan": "7331925c247b03b7767b8cd93cfe1b7aa2377850",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "710c69dbaccdac312e32931abcb8499c1525d397",
              "lessThan": "7a619f8c869117ffed08365b377f66b7e1d941b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "710c69dbaccdac312e32931abcb8499c1525d397",
              "lessThan": "db5a5406fb7e5337a074385c7a3e53c77f2c1bd3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1d86f79287206deec36d63b89c741cf542b6cadd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.150",
              "lessThan": "5.15.195",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.80",
              "lessThan": "6.1.156",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.19",
              "lessThan": "6.6.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.7.7",
              "lessThan": "6.8",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/fc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.195",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/fc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-11-12T11:15:47.513",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/060ecc81240ef9d60d9485a3a5eb55a0d6e7a25c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/11269c08013f4ee8b8f5edc6c56700acb34092d0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7331925c247b03b7767b8cd93cfe1b7aa2377850",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a619f8c869117ffed08365b377f66b7e1d941b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a28112cc55013cd8cbd5d36b5115a5b851151bd9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/db5a5406fb7e5337a074385c7a3e53c77f2c1bd3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: move lsop put work to nvmet_fc_ls_req_op\n\nIt’s possible for more than one async command to be in flight from\n__nvmet_fc_send_ls_req. For each command, a tgtport reference is taken.\n\nIn the current code, only one put work item is queued at a time, which\nresults in a leaked reference.\n\nTo fix this, move the work item to the nvmet_fc_ls_req_op struct, which\nalready tracks all resources related to the command."
    }
  ],
  "lastModified": "2026-07-30T06:24:15.820",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}