CVE-2025-21927
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 1, 2025
Updated: Apr 11, 2025
CWE ID 787
Summary
CVE-2025-21927 is a vulnerability affecting the Linux kernel's nvme-tcp driver. The issue lies in the function nvme_tcp_recv_pdu(), which fails to verify the validity of header lengths in incoming packets. When header digests are enabled, a malicious target can send packets with incorrect header lengths, causing memory corruption by overwriting the allocated area with calculated digests. The vulnerability can lead to potential memory corruption and system instability. The issue has been addressed by rejecting packets with unexpected header lengths.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.