Executive brief
A vulnerability was discovered in the Linux kernel's handling of secure network file sharing (NFS over TLS). The flaw exists in how the system processes security alerts during encrypted communications, which could allow a remote attacker to compromise the server. This could lead to unauthorized access to sensitive data, data modification, or a complete system shutdown, impacting business operations and data confidentiality.
Technical details
A vulnerability exists in the Linux kernel's SUNRPC component, specifically within the handling of server-side TLS alerts in NFS over TLS. The issue stems from an improper assumption in `tls_alert_recv()` regarding its ability to read data from the message iterator's `kvec`. In the kTLS implementation, non-data record payloads are split between the control message buffer and the message payload buffer. An attacker can exploit this by sending specific TLS control messages that cause the message iterator to advance incorrectly, leading to memory safety issues or improper state handling. The fix involves reworking how control messages are configured in `sock_recvmsg()` and ensuring the iterator is reverted before calling `tls_alert_recv`. Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, 6.15.y, and 6.16.y.
Affected products
- Linux Linux Kernel 6.4 to 6.6.102, 6.7 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1
Timeline
- 2025-08-15: patched: Fixes committed to stable kernel trees.
- 2025-08-19: advisory: CVE-2025-38566 published.
References
- https://git.kernel.org/stable/c/25bb3647d30a20486b5fe7cff2b0e503c16c9692
- https://git.kernel.org/stable/c/3b549da875414989f480b66835d514be80a0bd9c
- https://git.kernel.org/stable/c/6b33c31cc788073bfbed9297e1f4486ed73d87da
- https://git.kernel.org/stable/c/b1df394621710b312f0393e3f240fdac0764f968
- https://git.kernel.org/stable/c/bee47cb026e762841f3faece47b51f985e215edb