Bug 2356593 (CVE-2025-21927)

Summary: CVE-2025-21927 kernel: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aruffin, dfreiber, drow, jburrell, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
An unchecked buffer bounds flaw was found in the Linux kernel's NVMe TCP Fabrics driver. An attacker with the ability to send a crafted packet to an affected NVMe host could exploit this flaw to alter kernel memory, leading to an escalation of privileges or a compromise of system integrity or stability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-04-01 16:01:32 UTC
In the Linux kernel, the following vulnerability has been resolved:

nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()

nvme_tcp_recv_pdu() doesn't check the validity of the header length.
When header digests are enabled, a target might send a packet with an
invalid header length (e.g. 255), causing nvme_tcp_verify_hdgst()
to access memory outside the allocated area and cause memory corruptions
by overwriting it with the calculated digest.

Fix this by rejecting packets with an unexpected header length.

Comment 2 errata-xmlrpc 2025-04-30 00:19:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:4340 https://access.redhat.com/errata/RHSA-2025:4340

Comment 3 errata-xmlrpc 2025-04-30 00:38:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:4339 https://access.redhat.com/errata/RHSA-2025:4339

Comment 4 errata-xmlrpc 2025-04-30 01:02:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:4341 https://access.redhat.com/errata/RHSA-2025:4341

Comment 5 aruffin@redhat.com 2025-04-30 14:55:20 UTC
Hello,

https://access.redhat.com/errata/RHSA-2025:4339 is giving a 404 error when I visit it.  Is the URL correct?

Comment 6 aruffin@redhat.com 2025-05-05 17:35:46 UTC
Disregard, the link loads fine now

Comment 7 errata-xmlrpc 2025-05-05 17:56:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:4469 https://access.redhat.com/errata/RHSA-2025:4469

Comment 8 errata-xmlrpc 2025-05-05 18:09:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:4471 https://access.redhat.com/errata/RHSA-2025:4471

Comment 9 errata-xmlrpc 2025-05-06 00:48:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:4498 https://access.redhat.com/errata/RHSA-2025:4498

Comment 10 errata-xmlrpc 2025-05-06 00:49:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:4496 https://access.redhat.com/errata/RHSA-2025:4496

Comment 11 errata-xmlrpc 2025-05-06 00:51:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:4497 https://access.redhat.com/errata/RHSA-2025:4497

Comment 12 errata-xmlrpc 2025-05-06 01:04:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:4499 https://access.redhat.com/errata/RHSA-2025:4499

Comment 13 errata-xmlrpc 2025-05-06 07:08:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:4509 https://access.redhat.com/errata/RHSA-2025:4509

Comment 15 errata-xmlrpc 2025-05-13 11:55:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:7423 https://access.redhat.com/errata/RHSA-2025:7423

Comment 16 errata-xmlrpc 2025-05-13 15:59:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:7501 https://access.redhat.com/errata/RHSA-2025:7501