CVE-2025-38264
MEDIUMLinux Kernel 5.0-6.12.35, 6.13.0-6.15.4, 6.16+ - Request List Injection via Malicious R2T PDU
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
3.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (11)
linux/Kernel
5.0.0 - 6.12.36linux
linux/Kernel
6.13.0 - 6.15.5linux
Linux/Linux
< 5.0
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 0bf04c874fcb1ae46a863034296e4b33d8fbd66c
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 78a4adcd3fedb0728436e8094848ebf4c6bae006
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - f054ea62598197714a6ca7b3b387a027308f8b13
Linux/Linux
5.0
Linux/Linux
6.12.36 - 6.12.*
Linux/Linux
6.15.5 - 6.15.*
Linux/Linux
6.16
... and 1 more
Published
Jul 09, 2025
Tracked Since
Feb 18, 2026