CVE-2025-40259
Linux Kernel - Denial of Service via SCSI sg_finish_rem_req Interrupt Context
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.
References (8)
Core 8
Core References
Scores
EPSS
0.0006
EPSS Percentile
18.3%
Details
Status
published
Products (35)
linux/Kernel
4.12.0 - 5.4.302linux
linux/Kernel
5.11.0 - 5.15.197linux
linux/Kernel
5.16.0 - 6.1.159linux
linux/Kernel
5.5.0 - 5.10.247linux
linux/Kernel
6.13.0 - 6.17.10linux
linux/Kernel
6.2.0 - 6.6.118linux
linux/Kernel
6.7.0 - 6.12.60linux
Linux/Linux
< 4.12
Linux/Linux
3.16.85 - 3.17
Linux/Linux
3.18.101 - 3.19
... and 25 more
Published
Dec 04, 2025
Tracked Since
Feb 18, 2026