Answer in brief
CVE-2025-38264 records a Unknown severity vulnerability in nvme-tcp: sanitize request list handling. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <78a4adcd3fedb0728436e8094848ebf4c6bae006 || >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <f054ea62598197714a6ca7b3b387a027308f8b13 || >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <0bf04c874fcb1ae46a863034296e4b33d8fbd66c | 78a4adcd3fedb0728436e8094848ebf4c6bae006, f054ea62598197714a6ca7b3b387a027308f8b13, 0bf04c874fcb1ae46a863034296e4b33d8fbd66c |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Jul 9, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-38264 records a Unknown severity vulnerability in nvme-tcp: sanitize request list handling. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <78a4adcd3fedb0728436e8094848ebf4c6bae006 || >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <f054ea62598197714a6ca7b3b387a027308f8b13 || >=3f2304f8c6d6ed97849057bd16fee99e434ca796 <0bf04c874fcb1ae46a863034296e4b33d8fbd66c | 78a4adcd3fedb0728436e8094848ebf4c6bae006, f054ea62598197714a6ca7b3b387a027308f8b13, 0bf04c874fcb1ae46a863034296e4b33d8fbd66c |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Jul 9, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.
Quoted source text, attributed separately from HOL analysis.