CVE-2025-40118: scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
Since commit f7b705c238d1 ("scsi: pm80xx: Set phy_attached to zero when
device is gone") UBSAN reports:
UBSAN: array-index-out-of-bounds in drivers/scsi/pm8001/pm8001_sas.c:786:17
index 28 is out of range for type 'pm8001_phy [16]'
on rmmod when using an expander.
For a direct attached device, attached_phy contains the local phy id.
For a device behind an expander, attached_phy contains the remote phy
id, not the local phy id.
I.e. while pm8001_ha will have pm8001_ha->chip->n_phy local phys, for a
device behind an expander, attached_phy can be much larger than
pm8001_ha->chip->n_phy (depending on the amount of phys of the
expander).
E.g. on my system pm8001_ha has 8 phys with phy ids 0-7. One of the
ports has an expander connected. The expander has 31 phys with phy ids
0-30.
The pm8001_ha->phy array only contains the phys of the HBA. It does not
contain the phys of the expander. Thus, it is wrong to use attached_phy
to index the pm8001_ha->phy array for a device behind an expander.
Thus, we can only clear phy_attached for devices that are directly
attached.
Security readout for executives and security teams
Plain-English summary
A Linux storage driver can access memory outside a fixed-size array when the pm80xx module is removed from a system using a SAS expander. The resulting kernel memory corruption could affect confidentiality, integrity, or availability. Exposure is limited to hosts using this specific driver and storage topology; directly attached devices do not trigger the described indexing error.
Executive priority
Prioritize remediation on storage servers that use pm80xx with SAS expanders, particularly where module lifecycle operations occur. This is a high-severity kernel memory-safety issue, but the narrow hardware and operational prerequisites reduce enterprise-wide urgency. Treat it as expedited infrastructure maintenance rather than evidence of an active internet-scale campaign.
Technical view
The pm80xx driver incorrectly uses an expander’s remote attached_phy identifier to index the HBA-local pm8001_ha->phy array. Remote identifiers can exceed the array’s local PHY count, producing an out-of-bounds access during rmmod. The correction limits clearing phy_attached to directly attached devices. The supplied CVSS v3.1 score is 7.8 with a local, low-complexity vector.
Likely exposure
Likely exposure is confined to Linux systems loading the pm80xx SCSI driver, connecting affected devices through a SAS expander, and unloading the module. Ordinary systems without this driver or topology are not implicated by the supplied description. The bundled version data is ambiguous, so kernel safety should be confirmed through vendor guidance or fix-commit inclusion.
Exploitation context
The supplied record is not in CISA KEV, and no cited source reports active exploitation. The documented trigger occurs locally during module removal on an expander-backed configuration. Although the CVSS vector specifies low privileges, practical permission requirements for unloading kernel modules may vary by system configuration. No remote attack path is documented.
Researcher notes
The observed example used remote PHY index 28 against a 16-element local array. Root cause is confusion between local HBA PHY identifiers and remote expander PHY identifiers. The supplied affected-version representation does not clearly preserve range semantics; validate individual builds by vendor advisory or commit ancestry. The sources establish the faulty access and fix, but not demonstrated exploitation outcomes.
Mitigation direction
Identify and prioritize systems loading pm80xx with SAS expanders.
Install a vendor kernel explicitly incorporating the applicable linked Linux stable fix.
Until patched, avoid unloading pm80xx on expander-backed systems where operationally feasible.
Consult distribution guidance for exact fixed builds because the bundled version status is ambiguous.
Validation and detection
Confirm whether pm80xx is loaded and attached storage uses a SAS expander.
Match the running kernel build against vendor guidance or an applicable stable fix commit.
Review kernel and UBSAN logs for pm8001_sas array-index-out-of-bounds reports.
In an authorized lab, confirm module removal no longer produces the bounds warning after updating.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-40118 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
9Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.