In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix timeout on deleted connection
NOPIN response timer may expire on a deleted connection and crash with such logs:
Did not receive response to NOPIN on CID: 0, failing connection for I_T Nexus (null),i,0x00023d000125,iqn.2017-01.com.iscsi.target,t,0x3d
BUG: Kernel NULL pointer dereference on read at 0x00000000 NIP strlcpy+0x8/0xb0 LR iscsitfillcxntimeouterrstats+0x5c/0xc0 [iscsitargetmod] Call Trace: iscsithandlenopinresponsetimeout+0xfc/0x120 [iscsitargetmod] calltimerfn+0x58/0x1f0 runtimersoftirq+0x740/0x860 _dosoftirq+0x16c/0x420 irqexit+0x188/0x1c0 timer_interrupt+0x184/0x410
That is because nopin response timer may be re-started on nopin timer expiration.
Stop nopin timer before stopping the nopin response timer to be sure that no one of them will be re-started.
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fe8421e853ef289e1324fcda004751c89dd9c18a",
"id": "CVE-2025-38075-0457e295",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@019ca2804f3fb49a7f8e56ea6aeaa1ff32724c27",
"id": "CVE-2025-38075-0be3e17a",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@571ce6b6f5cbaf7d24af03cad592fc0e2a54de35",
"id": "CVE-2025-38075-4bc1a642",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2c5081439c7ab8da08427befe427f0d732ebc9f9",
"id": "CVE-2025-38075-a9b63b4d",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6815846e0c3a62116a7da9740e3a7c10edc5c7e9",
"id": "CVE-2025-38075-bc2839ce",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3e6429e3707943078240a2c0c0b3ee99ea9b0d9c",
"id": "CVE-2025-38075-d9d1e1b0",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"69031725837101968193752239446503862256",
"161621556402997319619368224261921602967",
"228864436302468282016059501264827444780",
"72735225257975589750206995259942974506",
"321074870988499506506153494663607480818"
]
},
"target": {
"file": "drivers/target/iscsi/iscsi_target.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@87389bff743c55b6b85282de91109391f43e0814",
"id": "CVE-2025-38075-ef197782",
"deprecated": false,
"signature_version": "v1"
}
]