CVE Database
/

CVE-2025-38700

Back to search

CVE-2025-38700

Published: Sep 4, 2025

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn->dd_data is initialized unconditionally, even when no memory is allocated (dd_size == 0). This leads invalid pointer dereference during connection teardown. Fix by setting iscsi_conn->dd_data only if memory is actually allocated. Panic trace: ------------ iser: iser_create_fastreg_desc: Failed to allocate ib_fast_reg_mr err=-12 iser: iser_alloc_rx_descriptors: failed allocating rx descriptors / data buffers BUG: unable to handle page fault for address: fffffffffffffff8 RIP: 0010:swake_up_locked.part.5+0xa/0x40 Call Trace: complete+0x31/0x40 iscsi_iser_conn_stop+0x88/0xb0 [ib_iser] iscsi_stop_conn+0x66/0xc0 [scsi_transport_iscsi] iscsi_if_stop_conn+0x14a/0x150 [scsi_transport_iscsi] iscsi_if_rx+0x1135/0x1834 [scsi_transport_iscsi] ? netlink_lookup+0x12f/0x1b0 ? netlink_deliver_tap+0x2c/0x200 netlink_unicast+0x1ab/0x280 netlink_sendmsg+0x257/0x4f0 ? _copy_from_user+0x29/0x60 sock_sendmsg+0x5f/0x70

VendorProductVersions

Linux

Linux

affected
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < f53af99f441ee79599d8df6113a7144d74cf9153
affected
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < 9ea6d961566c7d762ed0204b06db05756fdda3b6
affected
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < fd5aad080edb501ab5c84b7623d612d0e3033403
affected
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < a145c269dc5380c063a20a0db7e6df2995962e9d
affected
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < 66a373f50b4249d57f5a88c7be9676f9d5884865

+4 more versions

Linux

Linux

affected
2.6.27
unaffected
0 - < 2.6.27
unaffected
5.4.297 - <= 5.4.*
unaffected
5.10.241 - <= 5.10.*
unaffected
5.15.190 - <= 5.15.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now