CVE-2025-38075
A critical bug in the Linux kernel’s iSCSI target module can cause a crash when a deleted connection’s NOPIN response timer expires. The issue has been fixed by the vendor.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel 6.15 and earlier, including Debian 11.0. Users running these kernels are affected.
Real-world impact
An attacker could trigger a kernel crash, leading to denial of service or potential privilege escalation if the crash is exploitable.
Why this severity
The CVSS score of 9.8 reflects the lack of authentication or user interaction required, the complete loss of confidentiality, integrity, and availability, and the high likelihood of exploitation due to the kernel’s privileged nature.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix (e.g., 6.15 or later).
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jun 18, 2025 · Jun 18, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/019ca2804f3fb49a7f…patch
- git.kernel.org/stable/c/2c5081439c7ab8da08…patch
- git.kernel.org/stable/c/3e6429e37079430782…patch
- git.kernel.org/stable/c/571ce6b6f5cbaf7d24…patch
- git.kernel.org/stable/c/6815846e0c3a62116a…patch
- git.kernel.org/stable/c/7f533cc5ee4c4436ce…patch
- git.kernel.org/stable/c/87389bff743c55b6b8…patch
- git.kernel.org/stable/c/fe8421e853ef289e13…patch
- lists.debian.org/debian-lts-announce/2025/10…third party advisory
- lists.debian.org/debian-lts-announce/2025/10…third party advisory