Executive brief
A vulnerability exists in the Linux kernel's pm80xx SCSI driver, which manages certain storage controllers. When a storage expander is used and the driver module is removed, the system may attempt to access memory outside of its intended boundaries. This could lead to system instability, crashes, or potentially allow an attacker to gain unauthorized access to sensitive information or escalate their privileges on the system.
Technical details
An array-index-out-of-bounds vulnerability exists in drivers/scsi/pm8001/pm8001_sas.c within the pm8001_dev_gone_notify function. The root cause is the incorrect use of a remote PHY ID from a SAS expander to index the local HBA PHY array (pm8001_ha->phy), which is sized only for local PHYs. When a device behind an expander is removed, the attached_phy ID can exceed the local array bounds, leading to an out-of-bounds memory access. This issue was introduced by a previous commit intended to clear PHY status. The vulnerability is reachable via local module removal (rmmod) and has been patched in multiple stable kernel branches by adding a check to ensure PHY status is only cleared for directly attached devices.
Affected products
- Linux Linux Kernel 5.4.293 to 5.4.301, 5.10.237 to 5.10.246, 5.15.181 to 5.15.195, 6.1.136 to 6.1.156, 6.6.89 to 6.6.112, 6.12.26 to 6.12.53, 6.14.5 to 6.15
Timeline
- 2025-08-14: patched: Initial fix authored by Niklas Cassel
- 2025-11-12: disclosed: CVE-2025-40118 published
References
- https://git.kernel.org/stable/c/251be2f6037fb7ab399f68cd7428ff274133d693
- https://git.kernel.org/stable/c/45acbf154befedd9bc135f5e031fe7855d1e6493
- https://git.kernel.org/stable/c/83ced3c206c292458e47c7fac54223abc7141585
- https://git.kernel.org/stable/c/9326a1541e1b7ed3efdbab72061b82cf01c6477a
- https://git.kernel.org/stable/c/9c671d4dbfbfb0d73cfdfb706afb36d9ad60a582
- https://git.kernel.org/stable/c/d94be0a6ae9ade706d4270e740bdb4f79953a7fc
- https://git.kernel.org/stable/c/e62251954a128a2d0fcbc19e5fa39e08935bb628