LiveActive security incident?Get immediate response
CVE Record

CVE-2025-40118: scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod Since commit f7b705c238d1 ("scsi: pm80xx: Set phy_attached to zero when device is gone") UBSAN reports: UBSAN: array-index-out-of-bounds in drivers/scsi/pm8001/pm8001_sas.c:786:17 index 28 is out of range for type 'pm8001_phy [16]' on rmmod when using an expander. For a direct attached device, attached_phy contains the local phy id. For a device behind an expander, attached_phy contains the remote phy id, not the local phy id. I.e. while pm8001_ha will have pm8001_ha->chip->n_phy local phys, for a device behind an expander, attached_phy can be much larger than pm8001_ha->chip->n_phy (depending on the amount of phys of the expander). E.g. on my system pm8001_ha has 8 phys with phy ids 0-7. One of the ports has an expander connected. The expander has 31 phys with phy ids 0-30. The pm8001_ha->phy array only contains the phys of the HBA. It does not contain the phys of the expander. Thus, it is wrong to use attached_phy to index the pm8001_ha->phy array for a device behind an expander. Thus, we can only clear phy_attached for devices that are directly attached.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux storage driver can access memory outside a fixed-size array when the pm80xx module is removed from a system using a SAS expander. The resulting kernel memory corruption could affect confidentiality, integrity, or availability. Exposure is limited to hosts using this specific driver and storage topology; directly attached devices do not trigger the described indexing error.

Executive priority

Prioritize remediation on storage servers that use pm80xx with SAS expanders, particularly where module lifecycle operations occur. This is a high-severity kernel memory-safety issue, but the narrow hardware and operational prerequisites reduce enterprise-wide urgency. Treat it as expedited infrastructure maintenance rather than evidence of an active internet-scale campaign.

Technical view

The pm80xx driver incorrectly uses an expander’s remote attached_phy identifier to index the HBA-local pm8001_ha->phy array. Remote identifiers can exceed the array’s local PHY count, producing an out-of-bounds access during rmmod. The correction limits clearing phy_attached to directly attached devices. The supplied CVSS v3.1 score is 7.8 with a local, low-complexity vector.

Likely exposure

Likely exposure is confined to Linux systems loading the pm80xx SCSI driver, connecting affected devices through a SAS expander, and unloading the module. Ordinary systems without this driver or topology are not implicated by the supplied description. The bundled version data is ambiguous, so kernel safety should be confirmed through vendor guidance or fix-commit inclusion.

Exploitation context

The supplied record is not in CISA KEV, and no cited source reports active exploitation. The documented trigger occurs locally during module removal on an expander-backed configuration. Although the CVSS vector specifies low privileges, practical permission requirements for unloading kernel modules may vary by system configuration. No remote attack path is documented.

Researcher notes

The observed example used remote PHY index 28 against a 16-element local array. Root cause is confusion between local HBA PHY identifiers and remote expander PHY identifiers. The supplied affected-version representation does not clearly preserve range semantics; validate individual builds by vendor advisory or commit ancestry. The sources establish the faulty access and fix, but not demonstrated exploitation outcomes.

Mitigation direction

  • Identify and prioritize systems loading pm80xx with SAS expanders.
  • Install a vendor kernel explicitly incorporating the applicable linked Linux stable fix.
  • Until patched, avoid unloading pm80xx on expander-backed systems where operationally feasible.
  • Consult distribution guidance for exact fixed builds because the bundled version status is ambiguous.

Validation and detection

  • Confirm whether pm80xx is loaded and attached storage uses a SAS expander.
  • Match the running kernel build against vendor guidance or an applicable stable fix commit.
  • Review kernel and UBSAN logs for pm8001_sas array-index-out-of-bounds reports.
  • In an authorized lab, confirm module removal no longer produces the bounds warning after updating.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-40118 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
9Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2025-40118Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux05b512879eab41faa515b67fa3896d0005e97909, bc2140c8136200b4437e1abc0fb659968cb9baab, 1d8f9378cb4800c18e20d80ecd605b2b93e87a03, 30e482dfb8f27d22f518695d4bcb5e7f4c6cb08a, a862d24e1fc3ab1b5e5f20878d2898cea346d0ec, 0f9802f174227f553959422f844eeb9ba72467fe, f7b705c238d1483f0a766e2b20010f176e5c0fb7, f7b705c238d1483f0a766e2b20010f176e5c0fb7, 722026c010fa75bcf9e2373aff1d7930a3d7e3cf, 5.4.293, 5.10.237, 5.15.181, 6.1.136, 6.6.89, 6.12.26, 6.14.5unaffected
LinuxLinux6.15, 0, 5.4.301, 5.10.246, 5.15.195, 6.1.156, 6.6.112, 6.12.53, 6.17.3, 6.18affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.