CVE-2025-38264 | Linux Kernel up to 6.12.35/6.15.4 nvme_tcp_handle_r2t injection (EUVD-2025-20797 / Nessus ID 243457)
A vulnerability was found in Linux Kernel up to 6.12.35/6.15.4. It has been classified as problematic. Affected by this issue is the function nvme_tcp_handle_r2t. Performing a manipulation results in injection.
This vulnerability is cataloged as CVE-2025-38264. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.