cbcvebase.
CVE-2025-21690
published 2025-02-10

CVE-2025-21690: In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.4th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max out CPU utilization, preventing troubleshooting from the VM side. Ratelimit the warning so it doesn't DoS the VM.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < 81d4dd05c412ba04f9f6b85b718e6da833be290c81d4dd05c412ba04f9f6b85b718e6da833be290c
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < 182a4b7c731e95c08cb47f14b87a272b6ab2b2da182a4b7c731e95c08cb47f14b87a272b6ab2b2da
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < 088bde862f8d3d0fc52e40e66a0484a246837087088bde862f8d3d0fc52e40e66a0484a246837087
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < 01d1ebdab9ccb73c952e1666a8a80abd194dbc5501d1ebdab9ccb73c952e1666a8a80abd194dbc55
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < d0f0af1bafef33b3e2aa8c3a4ef44db48df9b0ead0f0af1bafef33b3e2aa8c3a4ef44db48df9b0ea
linuxlinux>= f8aea701b77c26732f151aab4f0a70e62eb53d86 < d2138eab8cde61e0e6f62d0713e45202e8457d6dd2138eab8cde61e0e6f62d0713e45202e8457d6d
linuxlinux_kernel< 5.15.1785.15.178
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.12-16.12.12-1
linuxlinux_kernel>= 0 < 6.12.12-16.12.12-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-62.656.8.0-62.65
linuxlinux_kernel>= 5.16 < 6.1.1286.1.128
linuxlinux_kernel>= 6.2 < 6.6.756.6.75
linuxlinux_kernel>= 6.7 < 6.12.126.12.12
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-3_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.