Resource management error in Linux kernel - CVE-2025-39778
Published: April 22, 2025 / Updated: May 10, 2025
Vulnerability identifier: #VU107772
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-39778
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the nvmet_ctrl_state_show() function in drivers/nvme/target/debugfs.c. A local user can perform a denial of service (DoS) attack.
How to mitigate CVE-2025-39778
Install update from vendor's website.
Sources
- https://git.kernel.org/stable/c/0cc0efc58d6c741b2868d4af24874d7fec28a575
- https://git.kernel.org/stable/c/107a23185d990e3df6638d9a84c835f963fe30a6
- https://git.kernel.org/stable/c/1adc93a525fdee8e2b311e6d5fd93eb69714ca05
- https://git.kernel.org/stable/c/8fbf37a3577b4d64c150cafde338eee17b2f2ea4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.11