nvme-fc: use lock accessing port_state and rport state
Published Dec 9, 2025
8.8
HIGHCVSS 3.1
EPSS 0.37%
Description
nvme_fc_unregister_remote removes the remote port on a lport object at any point in time when there is no active association. This races with with the reconnect logic, because nvme_fc_create_association is not taking a lock to check the port_state and atomically increase the active count on the rport.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.10
Unaffected
- ≥ 0, < 4.10
- ≥ 5.10.247, ≤ 5.10.*
- ≥ 5.15.197, ≤ 5.15.*
- ≥ 6.1.159, ≤ 6.1.*
- ≥ 6.12.58, ≤ 6.12.*
- ≥ 6.17.8, ≤ 6.17.*
- 6.18
- ≥ 6.6.117, ≤ 6.6.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2025-40342 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2420413 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201860 Advisory
- https://git.kernel.org/stable/c/25f4bf1f7979a7871974fd36c79d69ff1cf4b446
- https://git.kernel.org/stable/c/4253e0a4546138a2bf9cb6acf66b32fee677fc7c
- https://git.kernel.org/stable/c/891cdbb162ccdb079cd5228ae43bdeebce8597ad
- https://git.kernel.org/stable/c/9950af4303942081dc8c7a5fdc3688c17c7eb6c0
- https://git.kernel.org/stable/c/a2f7fa75c4a2a07328fa22ccbef461db76790b55
- https://git.kernel.org/stable/c/de3d91af47bc015031e7721b100a29989f6498a5
- https://git.kernel.org/stable/c/e8cde03de8674b05f2c5e0870729049eba517800
- https://lore.kernel.org/linux-cve-announce/2025120912-CVE-2025-40342-a237@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-40342
- https://www.cve.org/CVERecord?id=CVE-2025-40342
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data