CVE-2025-40343Linux vulnerability

50 documents8 sources
Severity
7.8HIGHOSV
OSV3.2
No vector
EPSS
0.1%
top 79.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateApr 13

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting down a port via the configfs interface, nvmet_port_subsys_drop_link() first calls nvmet_port_del_ctrls() and then nvmet_disable_port(). Both functions will eventually schedule all remaining associations for deletion. The current implementation checks whether an association is about to be removed, but only after the work item has already been schedu

Affected Packages7 packages

Linuxlinux/linux_kernel4.8.05.15.197+4
Debianlinux/linux_kernel< 6.1.159-1+2
Ubuntulinux/linux_kernel< 5.15.0-173.183+2
CVEListV5linux/linuxa07b4970f464f13640e28e16dad6cfa33647cc992f4852db87e25d4e226b25cb6f652fef9504360e+6

🔴Vulnerability Details

23
OSV
linux-raspi vulnerabilities2026-04-01
OSV
linux-raspi, linux-raspi-realtime vulnerabilities2026-04-01
OSV
linux-azure-6.8 vulnerabilities2026-03-25
OSV
linux-azure vulnerabilities2026-03-25
OSV
linux-intel-iot-realtime vulnerabilities2026-03-23

📋Vendor Advisories

25
Ubuntu
Linux kernel (Azure) vulnerabilities2026-04-13
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2026-04-09
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2026-04-09
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2026-04-01
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2026-04-01

🕵️Threat Intelligence

1
Wiz
CVE-2025-40343 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-40343 — Linux vulnerability | cvebase