VDB
Sign up
MEDIUM5.5

PYSEC-2026-1935

SPDK is vulnerable to buffer overflow in the NVMe-oF target component

Quick fix

PYSEC-2026-1935 — spdk: upgrade to the fixed version with the command below.

pip install --upgrade 'spdk>=25.9'

Details

Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/spdk
Introduced in: 0Fixed in: 25.9
Fixpip install --upgrade 'spdk>=25.9'

References