MEDIUM5.5
PYSEC-2026-1935
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
Quick fix
PYSEC-2026-1935 — spdk: upgrade to the fixed version with the command below.
pip install --upgrade 'spdk>=25.9'Details
Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-57275[ADVISORY]
- https://github.com/spdk/spdk/commit/8981ddb1ccaf54f85d34482a5a644e075b58cb36[WEB]
- https://github.com/spdk/spdk/commit/f786c6d75f5c5162363a621b24f5449c729679c9[WEB]
- https://github.com/spdk/spdk[PACKAGE]
- https://spdk.io[WEB]
- https://pypi.org/project/spdk[PACKAGE]
- https://github.com/advisories/GHSA-5m5w-w2h2-fqgq[ADVISORY]