CVE-2025-21690

MEDIUM

Linux Kernel < 5.15.178, 5.16.0-6.1.127, 6.2.0-6.6.74, 6.7.0-6.12.11, 6.13.0 - DoS via SCSI I/O Error Log Flood

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max out CPU utilization, preventing troubleshooting from the VM side. Ratelimit the warning so it doesn't DoS the VM.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (21)
linux/Kernel 4.5.0 - 5.15.178linux
linux/Kernel 5.16.0 - 6.1.128linux
linux/Kernel 6.13.0 - 6.13.1linux
linux/Kernel 6.2.0 - 6.6.75linux
linux/Kernel 6.7.0 - 6.12.12linux
Linux/Linux < 4.5
Linux/Linux 4.5
Linux/Linux 5.15.178 - 5.15.*
Linux/Linux 6.1.128 - 6.1.*
Linux/Linux 6.12.12 - 6.12.*
... and 11 more
Published Feb 10, 2025
Tracked Since Feb 18, 2026