CVE-2025-40259

Linux Kernel - Denial of Service via SCSI sg_finish_rem_req Interrupt Context

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.

Scores

EPSS 0.0006
EPSS Percentile 18.3%

Details

Status published
Products (35)
linux/Kernel 4.12.0 - 5.4.302linux
linux/Kernel 5.11.0 - 5.15.197linux
linux/Kernel 5.16.0 - 6.1.159linux
linux/Kernel 5.5.0 - 5.10.247linux
linux/Kernel 6.13.0 - 6.17.10linux
linux/Kernel 6.2.0 - 6.6.118linux
linux/Kernel 6.7.0 - 6.12.60linux
Linux/Linux < 4.12
Linux/Linux 3.16.85 - 3.17
Linux/Linux 3.18.101 - 3.19
... and 25 more
Published Dec 04, 2025
Tracked Since Feb 18, 2026