๐Ÿ” CVE Alert

CVE-2025-38700

UNKNOWN 0.0

scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn->dd_data is initialized unconditionally, even when no memory is allocated (dd_size == 0). This leads invalid pointer dereference during connection teardown. Fix by setting iscsi_conn->dd_data only if memory is actually allocated. Panic trace: ------------ iser: iser_create_fastreg_desc: Failed to allocate ib_fast_reg_mr err=-12 iser: iser_alloc_rx_descriptors: failed allocating rx descriptors / data buffers BUG: unable to handle page fault for address: fffffffffffffff8 RIP: 0010:swake_up_locked.part.5+0xa/0x40 Call Trace: complete+0x31/0x40 iscsi_iser_conn_stop+0x88/0xb0 [ib_iser] iscsi_stop_conn+0x66/0xc0 [scsi_transport_iscsi] iscsi_if_stop_conn+0x14a/0x150 [scsi_transport_iscsi] iscsi_if_rx+0x1135/0x1834 [scsi_transport_iscsi] ? netlink_lookup+0x12f/0x1b0 ? netlink_deliver_tap+0x2c/0x200 netlink_unicast+0x1ab/0x280 netlink_sendmsg+0x257/0x4f0 ? _copy_from_user+0x29/0x60 sock_sendmsg+0x5f/0x70

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2025
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < f53af99f441ee79599d8df6113a7144d74cf9153 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < 9ea6d961566c7d762ed0204b06db05756fdda3b6 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < fd5aad080edb501ab5c84b7623d612d0e3033403 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < a145c269dc5380c063a20a0db7e6df2995962e9d 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < 66a373f50b4249d57f5a88c7be9676f9d5884865 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < 35782c32528d82aa21f84cb5ceb2abd3526a8159 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < a33d42b7fc24fe03f239fbb0880dd5b4b4b97c19 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < 2b242ea14386a510010eabfbfc3ce81a101f3802 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 < 3ea3a256ed81f95ab0f3281a0e234b01a9cae605
Linux / Linux
2.6.27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f53af99f441ee79599d8df6113a7144d74cf9153 git.kernel.org: https://git.kernel.org/stable/c/9ea6d961566c7d762ed0204b06db05756fdda3b6 git.kernel.org: https://git.kernel.org/stable/c/fd5aad080edb501ab5c84b7623d612d0e3033403 git.kernel.org: https://git.kernel.org/stable/c/a145c269dc5380c063a20a0db7e6df2995962e9d git.kernel.org: https://git.kernel.org/stable/c/66a373f50b4249d57f5a88c7be9676f9d5884865 git.kernel.org: https://git.kernel.org/stable/c/35782c32528d82aa21f84cb5ceb2abd3526a8159 git.kernel.org: https://git.kernel.org/stable/c/a33d42b7fc24fe03f239fbb0880dd5b4b4b97c19 git.kernel.org: https://git.kernel.org/stable/c/2b242ea14386a510010eabfbfc3ce81a101f3802 git.kernel.org: https://git.kernel.org/stable/c/3ea3a256ed81f95ab0f3281a0e234b01a9cae605 lists.debian.org: https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html lists.debian.org: https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-032379.html