CVE-2025-39778
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 18, 2025
Updated: Apr 28, 2025
CWE ID 125
Summary
CVE-2025-39778: A vulnerability affecting the Linux kernel has been addressed. The issue lies in the 'nvmet' module, specifically in the 'nvmet_ctrl_state_show()' function. This function contained an out-of-bounds stack access due to an iteration error, allowing for potential stack reads. The 'csts_state_names[]' array only had six sparse entries, but the function iterated seven times, leading to this issue. This flaw resulted in a warning during kernel compilation with UBSAN. The vulnerability has now been remedied.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX