Junglewise Threat Intelligence

CVE-2025-38430: Linux Kernel nfsd undefined behavior in nfsd4_spo_must_allow

CVE-2025-38430 · Severity: medium · CVSS 5.5 · Published 2025-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Network File System (NFS) server component. The issue occurs when the server processes certain types of network requests without properly verifying their format, which can lead to unpredictable system behavior or instability. This could potentially allow a remote user to cause a service disruption, affecting the availability of shared files and corporate data storage.

Technical details

A vulnerability in the Linux kernel's NFS server (nfsd) arises because the function nfsd4_spo_must_allow() does not verify that an incoming RPC procedure is specifically an NFSPROC4_COMPOUND request before accessing the compound state (cstate). If a non-v4 compound request is processed, examining the cstate leads to undefined results due to improper state assumptions. This is a logic error in the NFSv4 server implementation. An attacker could potentially exploit this via network-reachable NFS services to cause kernel instability or a denial of service. The fix introduces a check to ensure rq_procinfo matches NFSPROC4_COMPOUND and that the minor version is not zero.

Affected products

  • Linux Linux Kernel All versions prior to the July 2025 patches

Timeline

  • 2025-03-28: other: Patch authored by Neil Brown
  • 2025-07-25: disclosed: CVE published

References

Related threats