-

CVE-2025-38405

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix memory leak of bio integrity

If nvmet receives commands with metadata there is a continuous memory
leak of kmalloc-128 slab or more precisely bio->bi_integrity.

Since commit bf4c89fc8797 ("block: don't call bio_uninit from bio_endio")
each user of bio_init has to use bio_uninit as well. Otherwise the bio
integrity is not getting free. Nvmet uses bio_init for inline bios.

Uninit the inline bio to complete deallocation of integrity in bio.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 431e58d56fcb5ff1f9eb630724a922e0d2a941df
Version bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f
Status affected
Version < 2e2028fcf924d1c6df017033c8d6e28b735a0508
Version bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f
Status affected
Version < 190f4c2c863af7cc5bb354b70e0805f06419c038
Version bf4c89fc8797f5c0964a0c3d561fbe7e8483b62f
Status affected
Version 64149da0fddbbfe43e11c0348d8c8b4171dae3a2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 6.11
Status affected
Version < 6.11
Version 0
Status unaffected
Version <= 6.12.*
Version 6.12.37
Status unaffected
Version <= 6.15.*
Version 6.15.6
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.055
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string