CVE-2025-38238 Information

Description

In the Linux kernel the following vulnerability has been resolved:

scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out

When both the RHBA and RPA FDMI requests time out fnic reuses a frame to send ABTS for each of them. On send completion this causes an attempt to free the same frame twice that leads to a crash.

Fix crash by allocating separate frames for RHBA and RPA and modify ABTS logic accordingly.

Tested by checking MDS for FDMI information.

Tested by using instrumented driver to:

  • Drop PLOGI response
  • Drop RHBA response
  • Drop RPA response
  • Drop RHBA and RPA response
  • Drop PLOGI response + ABTS response
  • Drop RHBA response + ABTS response
  • Drop RPA response + ABTS response
  • Drop RHBA and RPA response + ABTS response for both of them

Reference

https://git.kernel.org/stable/c/09679e9abedfbc5a2590759a1a7893c1c26e6044 https://git.kernel.org/stable/c/a35b29bdedb4d2ae3160d4d6684a6f1ecd9ca7c2

CNNVD-202507-1281 (Published: 2025-07-09)

Share on: