Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2025-21690— scsi: storvsc: Ratelimit warning logs to prevent VM denial of service

EPSS 0.01% · P2

Affected Version Matrix 14

VendorProductVersion RangeStatus
LinuxLinuxf8aea701b77c26732f151aab4f0a70e62eb53d86< 81d4dd05c412ba04f9f6b85b718e6da833be290caffected
f8aea701b77c26732f151aab4f0a70e62eb53d86< 182a4b7c731e95c08cb47f14b87a272b6ab2b2daaffected
f8aea701b77c26732f151aab4f0a70e62eb53d86< 088bde862f8d3d0fc52e40e66a0484a246837087affected
f8aea701b77c26732f151aab4f0a70e62eb53d86< 01d1ebdab9ccb73c952e1666a8a80abd194dbc55affected
f8aea701b77c26732f151aab4f0a70e62eb53d86< d0f0af1bafef33b3e2aa8c3a4ef44db48df9b0eaaffected
f8aea701b77c26732f151aab4f0a70e62eb53d86< d2138eab8cde61e0e6f62d0713e45202e8457d6daffected
4.5affected
< 4.5unaffected
… +6 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21690

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
scsi: storvsc: Ratelimit warning logs to prevent VM denial of service
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max out CPU utilization, preventing troubleshooting from the VM side. Ratelimit the warning so it doesn't DoS the VM.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。攻击者利用该漏洞可以导致程序拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f8aea701b77c26732f151aab4f0a70e62eb53d86 ~ 81d4dd05c412ba04f9f6b85b718e6da833be290c -
LinuxLinux 4.5 -

II. Public POCs for CVE-2025-21690

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21690

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-02-10 · 8 CVEs total

CVE-2024-57950drm/amd/display: Initialize denominator defaults to 1
CVE-2025-21687vfio/platform: check the bounds of read/write syscalls
CVE-2025-21689USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()
CVE-2025-21688drm/v3d: Assign job pointer to NULL before signaling the fence
CVE-2025-21691cachestat: fix page cache statistics permission checking
CVE-2025-21692net: sched: fix ets qdisc OOB Indexing
CVE-2025-21693mm: zswap: properly synchronize freeing resources during CPU hotunplug

IV. Related Vulnerabilities

V. Comments for CVE-2025-21690

No comments yet


Leave a comment