Home / Security / Advisories / NTAP-20260925-0007

NTAP-20260925-0007 — CVE-2025-40347 Linux Kernel Vulnerability in NetApp Products

Published 2026-09-25 · Updated 2026-09-25 · Status: Interim · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes

Official advisory: NTAP-20260925-0007 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Baseboard management controllers · Active IQ Unified Manager · Brocade SAN firmware · ONTAP · Other NetApp products · NetApp Console / BlueXP · SolidFire / NetApp HCI · SnapCenter  |  ONTAP-relevant  |  highest CVSS: 7.5

CVEs in this advisory

What the CVE records say

CVE-2025-40347 — In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix the deadlock of enetc_mdio_lock After applying the workaround for err050089, the LS1028A platform experiences RCU stalls on RT kernel. This issue is caused by the recursive acquisition of the read lock enetc_mdio_lock. Here list some of the call stacks identified under the enetc_poll path that may lead to a deadlock: enetc_poll -> enetc_lock_mdio -> enetc_clean_rx_ring OR napi_complete_done -> napi_gro_receive -> enetc_start_xmit -> enetc_lock_mdio -> enetc_map_tx_buffs -> enetc_unlock_mdio -> enetc_unlock_mdio After enetc_poll acquires the read lock, a higher-priority writer attempts to acquire the lock, causing preemption. The writer detects that a read lock is already held and is scheduled out. However, readers under enetc_poll cannot acquire the read lock again because a writer is already waiting, leading to a thread hang. Currently, the deadlock is avoided by adjusting enetc_lock_mdio to prevent recursive lock acquisition.

Impact

Successful exploitation of this vulnerability could lead to Denial of Service (DoS).

Affected products

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub