CVE-2025-39778 | Linux Kernel up to 6.12.22/6.13.10/6.14.1 nvmet_ctrl_state_show csts_state_names[] out-of-bounds (Nessus ID 240657 / WID-SEC-2025-0861)
A vulnerability classified as problematic has been found in Linux Kernel up to 6.12.22/6.13.10/6.14.1. This impacts the function nvmet_ctrl_state_show. The manipulation of the argument csts_state_names[] leads to out-of-bounds read.
This vulnerability is listed as CVE-2025-39778. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.