CVE-2025-21690
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max out CPU utilization, preventing troubleshooting from the VM side. Ratelimit the warning so it doesn't DoS the VM.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.20%• Percentile: 10%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- linux•linux
≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < 81d4dd05c412ba04f9f6b85b718e6da833be290c | ≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < 182a4b7c731e95c08cb47f14b87a272b6ab2b2da | ≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < 088bde862f8d3d0fc52e40e66a0484a246837087 | ≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < 01d1ebdab9ccb73c952e1666a8a80abd194dbc55 | ≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < d0f0af1bafef33b3e2aa8c3a4ef44db48df9b0ea | ≥ f8aea701b77c26732f151aab4f0a70e62eb53d86, < d2138eab8cde61e0e6f62d0713e45202e8457d6d | 4.5
- linux•linux kernel
< 5.15.178 | ≥ 5.16, < 6.1.128 | ≥ 6.2, < 6.6.75 | ≥ 6.7, < 6.12.12 | 6.13 | 6.13:rc1 | 6.13:rc2 | 6.13:rc3 | 6.13:rc4 | 6.13:rc5 | 6.13:rc6 | 6.13:rc7
References (7)
- https://git.kernel.org/stable/c/81d4dd05c412ba04f9f6b85b718e6da833be290c
- https://git.kernel.org/stable/c/182a4b7c731e95c08cb47f14b87a272b6ab2b2da
- https://git.kernel.org/stable/c/088bde862f8d3d0fc52e40e66a0484a246837087
- https://git.kernel.org/stable/c/01d1ebdab9ccb73c952e1666a8a80abd194dbc55
- https://git.kernel.org/stable/c/d0f0af1bafef33b3e2aa8c3a4ef44db48df9b0ea
- https://git.kernel.org/stable/c/d2138eab8cde61e0e6f62d0713e45202e8457d6d
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html