CVE-2025-40171 - CVE House
Back to Database
Status published Unknown CVE-2025-40171

nvmet-fc: move lsop put work to nvmet_fc_ls_req_op

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: move lsop put work to nvmet_fc_ls_req_op It’s possible for more than one async command to be in flight from __nvmet_fc_send_ls_req. For each command, a tgtport reference is taken. In the current code, only one put work item is queued at a time, which results in a leaked reference. To fix this, move the work item to the nvmet_fc_ls_req_op struct, which already tracks all resources related to the command.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40171

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
5e0bc09a52b6169ce90f7ac6e195791adb16cec4, 9e6987f8937a7bd7516aa52f25cb7e12c0c92ee8, eaf0971fdabf2a93c1429dc6bedf3bbe85dffa30, 710c69dbaccdac312e32931abcb8499c1525d397, 1d86f79287206deec36d63b89c741cf542b6cadd, 5.15.150, 6.1.80, 6.6.19, 6.7.7, 6.8, 0, 5.15.195, 6.1.156, 6.6.112, 6.12.53, 6.17.3, 6.18

Timeline

Official Publish: November 12th, 2025
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.