CVE-2025-21927

nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()

References

Notes

 carnil> Introduced in 3f2304f8c6d6 ("nvme-tcp: add NVMe over TCP host driver").
 carnil> Vulnerable versions: 5.0.

Bugs

Status

Branch Status
upstream released (6.14-rc6) [ad95bab0cd28ed77c2c0d0b6e76e03e031391064]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.13-upstream-stable released (6.13.7) [22b06c89aa6b2d1ecb8aea72edfb9d53af8d5126]
6.12-upstream-stable released (6.12.19) [9fbc953d6b38bc824392e01850f0aeee3b348722]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.12.19-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security needed