CVE-2025-38264

MEDIUM

Linux Kernel 5.0-6.12.35, 6.13.0-6.15.4, 6.16+ - Request List Injection via Malicious R2T PDU

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (11)
linux/Kernel 5.0.0 - 6.12.36linux
linux/Kernel 6.13.0 - 6.15.5linux
Linux/Linux < 5.0
Linux/Linux 3f2304f8c6d6ed97849057bd16fee99e434ca796 - 0bf04c874fcb1ae46a863034296e4b33d8fbd66c
Linux/Linux 3f2304f8c6d6ed97849057bd16fee99e434ca796 - 78a4adcd3fedb0728436e8094848ebf4c6bae006
Linux/Linux 3f2304f8c6d6ed97849057bd16fee99e434ca796 - f054ea62598197714a6ca7b3b387a027308f8b13
Linux/Linux 5.0
Linux/Linux 6.12.36 - 6.12.*
Linux/Linux 6.15.5 - 6.15.*
Linux/Linux 6.16
... and 1 more
Published Jul 09, 2025
Tracked Since Feb 18, 2026