Executive brief
A vulnerability in the Linux kernel's Parallel NFS (pNFS) implementation could allow a local user to crash the system. The issue occurs when the system handles large files with many data segments (extents) using block or SCSI storage layouts. An exploit could lead to a denial-of-service condition, impacting system availability and ongoing operations.
Technical details
An uninitialized pointer dereference vulnerability exists in the Linux kernel's pNFS block/SCSI layout component within `fs/nfs/blocklayout/extent_tree.c`. The root cause is located in `ext_tree_prepare_commit()`, where the `layoutupdate_pages` array is initialized only after a retry loop, yet `ext_tree_free_commitdata()` is called during each iteration of that loop. When encoding a large number of extents (e.g., when writing to a large file without preallocation), the buffer reallocation logic triggers a retry that dereferences these uninitialized pointers. Additionally, the lack of a maximum buffer size limit can cause the client to generate layout commits exceeding the server's maximum RPC size. This is a local attack vector requiring low privileges, resulting in a kernel panic (Denial of Service). Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.18 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-04: advisory: Initial publication of CVE-2025-38691
- 2025-08-28: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/24334f3cf8a294f253071b5bf22d754dbb6d0f2d
- https://git.kernel.org/stable/c/2896f101110076ac6bf99d7aaf463d61e26f89dd
- https://git.kernel.org/stable/c/37c3443a2685528f972d910a6fb87716b96fef46
- https://git.kernel.org/stable/c/4f783333cbfa2ee7d4aa8e47f6bd1b3f77534fcf
- https://git.kernel.org/stable/c/579b85f893d9885162e1cabf99a4a088916e143e
- https://git.kernel.org/stable/c/94ec6d939031a616474376dadbf4a8d0ef8b0bcc
- https://git.kernel.org/stable/c/9768797c219326699778fba9cd3b607b2f1e7950