Buffer overflow in Storage Performance Development Kit (spdk) - CVE-2025-57275
Published: October 28, 2025
Vulnerability identifier: #VU117690
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-57275
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the NVMe-oF target component in lib/nvmf. A remote authenticated user can trigger out-of-bounds memory access and perform a denial of service (DoS) attack.
Affected software
Storage Performance Development Kit (spdk)
openEuler
spdk-tools
spdk-devel
spdk-debugsource
spdk-debuginfo
spdk
openEuler
spdk-tools
spdk-devel
spdk-debugsource
spdk-debuginfo
spdk
How to mitigate CVE-2025-57275
Install updates from vendor's website.
Storage Performance Development Kit (spdk) - update to 25.05.1
spdk-tools - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-devel - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-debugsource - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-debuginfo - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-tools - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-devel - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-debugsource - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk-debuginfo - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11
spdk - addressed in versions 21.01.1-16, 21.01.1-18, 21.01-11, 24.01-10, 24.01-11