cbcvebase.
CVE-2025-39778
published 2025-04-18

CVE-2025-39778: In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse entries, but the iteration code in nvmet_ctrl_state_show() iterates seven, resulting in a potential out-of-bounds stack read. Fix that. Fixes the following warning with an UBSAN kernel: vmlinux.o: warning: objtool: .text.nvmet_ctrl_state_show: unexpected end of section

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux>= 649fd41420a816b11b07423ebf4dbd4ac1ac2905 < 1adc93a525fdee8e2b311e6d5fd93eb69714ca051adc93a525fdee8e2b311e6d5fd93eb69714ca05
linuxlinux>= 649fd41420a816b11b07423ebf4dbd4ac1ac2905 < 8fbf37a3577b4d64c150cafde338eee17b2f2ea48fbf37a3577b4d64c150cafde338eee17b2f2ea4
linuxlinux>= 649fd41420a816b11b07423ebf4dbd4ac1ac2905 < 0cc0efc58d6c741b2868d4af24874d7fec28a5750cc0efc58d6c741b2868d4af24874d7fec28a575
linuxlinux>= 649fd41420a816b11b07423ebf4dbd4ac1ac2905 < 107a23185d990e3df6638d9a84c835f963fe30a6107a23185d990e3df6638d9a84c835f963fe30a6
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.11 < 6.12.236.12.23
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.