Junglewise Threat Intelligence

CVE-2025-40171: Linux Kernel reference leak in nvmet-fc target driver

CVE-2025-40171 · Severity: high · CVSS 7.5 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's NVMe-over-Fibre Channel (NVMe-FC) target driver could allow a remote attacker to cause a denial-of-service condition. The issue stems from improper resource management when handling multiple simultaneous commands, which can lead to memory or reference leaks. Over time, this could exhaust system resources and cause the affected server to become unstable or crash.

Technical details

A reference counting vulnerability exists in the Linux kernel's NVMe-over-Fibre Channel (NVMe-FC) target implementation (drivers/nvme/target/fc.c). The function __nvmet_fc_send_ls_req takes a tgtport reference for each asynchronous command, but the driver previously only queued one 'put' work item at a time. This logic error results in leaked tgtport references when multiple commands are in flight. An attacker could potentially trigger this leak to exhaust system resources, leading to a kernel-level denial of service. The fix involves moving the work item to the nvmet_fc_ls_req_op struct to ensure each command's resources are tracked and released individually.

Affected products

  • Linux Linux Kernel 5.15.150 to 5.15.195, 6.1.80 to 6.1.156, 6.6.19 to 6.6.112, 6.7.7 to 6.8

Timeline

  • 2025-11-12: advisory: CVE-2025-40171 published by NVD/kernel.org

References

Related threats