Review reviewHigh

CVE-2025-40342

Linux

In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote removes the remote port on a lport object at any point in time when there is no active association. This races with with the reconnect logic, because nvme_fc_create_association is not taking a lock to check the port_state and atomically increase the active count on the rport.

CVSS
8.8
EPSS
0.33%
25.0% percentile
CISA KEV
Not listed
Published
2025.12.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.33%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nvme-fc: use lock accessing port_state and rport state nvme_fc_unregister_remote removes the remote port on a lport object at any point in time when there is no active association. This races with with the reconnect logic, because nvme_fc_create_association is not taking a lock to check the port_state and atomically increase the active count on the rport.

Affected product and versions

Product
Linux
Affected versions
>= e399441de9115cd472b8ace6c517708273ca7997 < de3d91af47bc015031e7721b100a29989f6498a5, >= e399441de9115cd472b8ace6c517708273ca7997 < e8cde03de8674b05f2c5e0870729049eba517800, >= e399441de9115cd472b8ace6c517708273ca7997 < 4253e0a4546138a2bf9cb6acf66b32fee677fc7c, >= e399441de9115cd472b8ace6c517708273ca7997 < 25f4bf1f7979a7871974fd36c79d69ff1cf4b446, >= e399441de9115cd472b8ace6c517708273ca7997 < 9950af4303942081dc8c7a5fdc3688c17c7eb6c0, >= e399441de9115cd472b8ace6c517708273ca7997 < a2f7fa75c4a2a07328fa22ccbef461db76790b55, >= e399441de9115cd472b8ace6c517708273ca7997 < 891cdbb162ccdb079cd5228ae43bdeebce8597ad, >= 4.10
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-40342 — Linux | SECUFOCUS NOW