CVE-2025-39998 (GCVE-0-2025-39998)
Vulnerability from cvelistv5
Published
2025-10-15 07:58
Modified
2026-08-05 12:07
Summary
In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/target_core_configfs.c. This buffer is allocated with size LU_GROUP_NAME_BUF (256 bytes). snprintf(...) formats multiple strings into buf with the HBA name (hba->hba_group.cg_item), a slash character, a devicename (dev-> dev_group.cg_item) and a newline character, the total formatted string length may exceed the buffer size of 256 bytes. Since snprintf() returns the total number of bytes that would have been written (the length of %s/%sn ), this value may exceed the buffer length (256 bytes) passed to memcpy(), this will ultimately cause function memcpy reporting a buffer overflow error. An additional check of the return value of snprintf() can avoid this buffer overflow.
Impacted products
Vendor Product Version
Linux Linux Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Version: c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/target/target_core_configfs.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e6eeee5dc0d9221ff96d1b229b1d0222c8871b84",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "764a91e2fc9639e07aac93bc70e387e6b1e33084",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "ddc79fba132b807ff775467acceaf48b456e008b",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "e73fe0eefac3e15bf88fb5b4afae4c76215ee4d4",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "f03aa5e39da7d045615b3951d2a6ca1d7132f881",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "53c6351597e6a17ec6619f6f060d54128cb9a187",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "4b292286949588bd2818e66ff102db278de8dd26",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "a150275831b765b0f1de8b8ff52ec5c6933ac15d",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            },
            {
              "lessThan": "27e06650a5eafe832a90fd2604f0c5e920857fae",
              "status": "affected",
              "version": "c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/target/target_core_configfs.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.38"
            },
            {
              "lessThan": "2.6.38",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.301",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.246",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.195",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.156",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.110",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.51",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.17.*",
              "status": "unaffected",
              "version": "6.17.1",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.301",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.246",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.195",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.156",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.110",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.51",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.11",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17.1",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18",
                  "versionStartIncluding": "2.6.38",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: target_core_configfs: Add length check to avoid buffer overflow\n\nA buffer overflow arises from the usage of snprintf to write into the\nbuffer \"buf\" in target_lu_gp_members_show function located in\n/drivers/target/target_core_configfs.c. This buffer is allocated with\nsize LU_GROUP_NAME_BUF (256 bytes).\n\nsnprintf(...) formats multiple strings into buf with the HBA name\n(hba-\u003ehba_group.cg_item), a slash character, a devicename (dev-\u003e\ndev_group.cg_item) and a newline character, the total formatted string\nlength may exceed the buffer size of 256 bytes.\n\nSince snprintf() returns the total number of bytes that would have been\nwritten (the length of %s/%sn ), this value may exceed the buffer length\n(256 bytes) passed to memcpy(), this will ultimately cause function\nmemcpy reporting a buffer overflow error.\n\nAn additional check of the return value of snprintf() can avoid this\nbuffer overflow."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is triggered by read(2) on a configfs attribute file at /sys/kernel/config/target/core/alua/lu_gps/\u003cgp\u003e/members, which requires local access to the system. There is no network-facing path into target_lu_gp_members_show().\nAC:L - The over-read is fully deterministic \u2014 once an HBA+device name pair exceeding 255 combined characters exists, every read of the members file executes memcpy() with a length larger than the 256-byte stack source, with no race or memory-layout dependency.\nPR:L - The members attribute is CONFIGFS_ATTR_RO (mode 0444) under 0755 configfs directories, so any unprivileged local account \u2014 or a container with /sys bind-mounted read-only \u2014 can perform the triggering read; only the pre-existing long backstore name is admin-created state, not a privilege the attacker must hold.\nUI:N - Exploitation is a single read() by the attacker with no victim action required. No administrator or other user must be induced to do anything at exploit time.\nS:U - The out-of-bounds read and the resulting disclosure/panic are confined to the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Up to ~65 bytes of kernel stack memory adjacent to buf[256] are copied into the configfs page and returned to userspace, plausibly leaking the stack canary, saved registers, and kernel/list pointers that defeat KASLR and stack protector. This is well beyond a \"few bytes\" bounded read.\nI:N - The (cur_len + len) \u003e PAGE_SIZE check correctly bounds the memcpy destination inside the get_zeroed_page() buffer, so no kernel memory is written out of bounds and no write or control-flow primitive is produced.\nA:H - With CONFIG_FORTIFY_SOURCE (default in distro kernels) the runtime source-size check in fortify_memcpy_chk() fires and calls fortify_panic(), producing a kernel BUG/panic; KASAN builds BUG as well, and the attacker can trigger this at will by re-reading the file."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:07:00.453Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e6eeee5dc0d9221ff96d1b229b1d0222c8871b84"
        },
        {
          "url": "https://git.kernel.org/stable/c/764a91e2fc9639e07aac93bc70e387e6b1e33084"
        },
        {
          "url": "https://git.kernel.org/stable/c/ddc79fba132b807ff775467acceaf48b456e008b"
        },
        {
          "url": "https://git.kernel.org/stable/c/e73fe0eefac3e15bf88fb5b4afae4c76215ee4d4"
        },
        {
          "url": "https://git.kernel.org/stable/c/f03aa5e39da7d045615b3951d2a6ca1d7132f881"
        },
        {
          "url": "https://git.kernel.org/stable/c/53c6351597e6a17ec6619f6f060d54128cb9a187"
        },
        {
          "url": "https://git.kernel.org/stable/c/4b292286949588bd2818e66ff102db278de8dd26"
        },
        {
          "url": "https://git.kernel.org/stable/c/a150275831b765b0f1de8b8ff52ec5c6933ac15d"
        },
        {
          "url": "https://git.kernel.org/stable/c/27e06650a5eafe832a90fd2604f0c5e920857fae"
        }
      ],
      "title": "scsi: target: target_core_configfs: Add length check to avoid buffer overflow",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39998",
    "datePublished": "2025-10-15T07:58:22.354Z",
    "dateReserved": "2025-04-16T07:20:57.151Z",
    "dateUpdated": "2026-08-05T12:07:00.453Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…