CVE-2025-21927

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 11, 2025
CWE ID 787

Summary

CVE-2025-21927 is a vulnerability affecting the Linux kernel's nvme-tcp driver. The issue lies in the function nvme_tcp_recv_pdu(), which fails to verify the validity of header lengths in incoming packets. When header digests are enabled, a malicious target can send packets with incorrect header lengths, causing memory corruption by overwriting the allocated area with calculated digests. The vulnerability can lead to potential memory corruption and system instability. The issue has been addressed by rejecting packets with unexpected header lengths.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share