cbcvebase.
CVE-2025-40342
published 2025-12-09

CVE-2025-40342: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote removes…

PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.33%
25.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote removes the remote port on a lport object at any point in time when there is no active association. This races with with the reconnect logic, because nvme_fc_create_association is not taking a lock to check the port_state and atomically increase the active count on the rport.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < de3d91af47bc015031e7721b100a29989f6498a5de3d91af47bc015031e7721b100a29989f6498a5
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < e8cde03de8674b05f2c5e0870729049eba517800e8cde03de8674b05f2c5e0870729049eba517800
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < 4253e0a4546138a2bf9cb6acf66b32fee677fc7c4253e0a4546138a2bf9cb6acf66b32fee677fc7c
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < 25f4bf1f7979a7871974fd36c79d69ff1cf4b44625f4bf1f7979a7871974fd36c79d69ff1cf4b446
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < 9950af4303942081dc8c7a5fdc3688c17c7eb6c09950af4303942081dc8c7a5fdc3688c17c7eb6c0
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < a2f7fa75c4a2a07328fa22ccbef461db76790b55a2f7fa75c4a2a07328fa22ccbef461db76790b55
linuxlinux>= e399441de9115cd472b8ace6c517708273ca7997 < 891cdbb162ccdb079cd5228ae43bdeebce8597ad891cdbb162ccdb079cd5228ae43bdeebce8597ad
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 4.10.0 < 5.10.2475.10.247
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.0HIGH
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.