In the Linux kernel, the following vulnerability has been resolved:
nvmet: Don't overflow subsysnqn
nvmet_root_discovery_nqn_store treats the subsysnqn string like a fixed size buffer, even though it is dynamically allocated to the size of the string.
Create a new string with kstrndup instead of using the old buffer.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | Upgrade kernelNo solution existsUpgrade kernel-rt | May 15, 2025 | Jan 15, 2025 |
| Ubuntu | — | Upgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1011-lowlatencyUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-6.11.0-1017-oemUpgrade linux-image-azure-fdeUpgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-6.11.0-1011-gcpUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-6.11.0-1012-azureUpgrade linux-image-oem-24.04bUpgrade linux-image-6.11.0-1011-awsUpgrade linux-image-awsUpgrade linux-image-6.11.0-1013-oracle-64kUpgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-gcp-64kUpgrade linux-image-raspiUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-genericUpgrade linux-image-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-azureUpgrade linux-image-lowlatency-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-lowlatencyUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-oem-24.04Upgrade linux-image-6.11.0-1007-realtime | Mar 28, 2025 | Jan 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub