CVE-2025-40343 — Linux vulnerability
50 documents8 sources
Severity
7.8HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 79.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
nvmet-fc: avoid scheduling association deletion twice
When forcefully shutting down a port via the configfs interface,
nvmet_port_subsys_drop_link() first calls nvmet_port_del_ctrls() and
then nvmet_disable_port(). Both functions will eventually schedule all
remaining associations for deletion.
The current implementation checks whether an association is about to be
removed, but only after the work item has already been schedu…
Affected Packages7 packages
▶CVEListV5linux/linuxa07b4970f464f13640e28e16dad6cfa33647cc99 — 2f4852db87e25d4e226b25cb6f652fef9504360e+6