CVE-2025-57275

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-57275
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-57275.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-57275
Aliases
Downstream
Published
2025-10-01T15:15:47Z
Modified
2025-10-23T04:21:39.879711Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.

References

Affected packages

Git / github.com/spdk/spdk

Affected ranges

Type
GIT
Repo
https://github.com/spdk/spdk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.0
v1.2.0

v16.*

v16.06
v16.08
v16.12

v17.*

v17.03
v17.07
v17.10

v18.*

v18.01
v18.04
v18.07
v18.10

v19.*

v19.01
v19.04
v19.07
v19.10-rc1

v20.*

v20.01-rc1
v20.04-rc1
v20.07-rc1
v20.10-rc1

v21.*

v21.01-rc1
v21.04-rc1
v21.07-rc1
v21.10-rc1

v22.*

v22.01-rc1
v22.05-rc1
v22.09-pre
v22.09-rc1

v23.*

v23.01-pre
v23.01-rc1
v23.05-pre
v23.05-rc1
v23.09-pre
v23.09-rc1

v24.*

v24.01-pre
v24.01-rc1
v24.05-pre
v24.05-rc1
v24.09-pre
v24.09-rc1

v25.*

v25.01-pre
v25.01-rc1
v25.05-pre
v25.05-rc1
v25.09-pre
v25.09-rc1

v26.*

v26.01-pre