cbcvebase.
CVE-2025-38405
published 2025-07-25

CVE-2025-38405: In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak of bio integrity If nvmet receives commands with metadata there is a…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.35%
28.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak of bio integrity If nvmet receives commands with metadata there is a continuous memory leak of kmalloc-128 slab or more precisely bio->bi_integrity. Since commit bf4c89fc8797 ("block: don't call bio_uninit from bio_endio") each user of bio_init has to use bio_uninit as well. Otherwise the bio integrity is not getting free. Nvmet uses bio_init for inline bios. Uninit the inline bio to complete deallocation of integrity in bio.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.37-1 (forky)linux 6.12.37-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.10.10 < 6.116.11
linuxlinux>= bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f < 431e58d56fcb5ff1f9eb630724a922e0d2a941df431e58d56fcb5ff1f9eb630724a922e0d2a941df
linuxlinux>= bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f < 2e2028fcf924d1c6df017033c8d6e28b735a05082e2028fcf924d1c6df017033c8d6e28b735a0508
linuxlinux>= bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f < 190f4c2c863af7cc5bb354b70e0805f06419c038190f4c2c863af7cc5bb354b70e0805f06419c038
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.12.37-16.12.37-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.10.10 < 6.12.376.12.37
linuxlinux_kernel>= 6.13 < 6.15.66.15.6
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_ubuntu5.6MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.