Review reviewHigh

CVE-2025-39998

Linux

In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/target_core_configfs.c. This buffer is allocated with size LU_GROUP_NAME_BUF (256 bytes). snprintf(...) formats multiple strings into buf with the HBA name (hba->hba_group.cg_item), a slash character, a devicename (dev-> dev_group.cg_item) and a newline character, the total formatted string length may...

CVSS
7.1
EPSS
-
- percentile
CISA KEV
Not listed
Published
2025.10.15
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/target_core_configfs.c. This buffer is allocated with size LU_GROUP_NAME_BUF (256 bytes). snprintf(...) formats multiple strings into buf with the HBA name (hba->hba_group.cg_item), a slash character, a devicename (dev-> dev_group.cg_item) and a newline character, the total formatted string length may...

Affected product and versions

Product
Linux
Affected versions
>= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < e6eeee5dc0d9221ff96d1b229b1d0222c8871b84, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < 764a91e2fc9639e07aac93bc70e387e6b1e33084, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < ddc79fba132b807ff775467acceaf48b456e008b, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < e73fe0eefac3e15bf88fb5b4afae4c76215ee4d4, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < f03aa5e39da7d045615b3951d2a6ca1d7132f881, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < 53c6351597e6a17ec6619f6f060d54128cb9a187, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < 4b292286949588bd2818e66ff102db278de8dd26, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < a150275831b765b0f1de8b8ff52ec5c6933ac15d, >= c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 < 27e06650a5eafe832a90fd2604f0c5e920857fae, >= 2.6.38
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
Not available