Executive brief
A vulnerability exists in the Linux kernel's Network File System (NFS) server component, which is used to share files across a network. A flaw in how the server handles client identification requests can lead to a system crash or allow unauthorized access to memory. This could result in a complete service outage or the theft of sensitive data stored on the server.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's NFSD (NFS server) implementation within the nfsd4_setclientid_confirm() function. The root cause is a failure to check the return value of get_client_locked(), allowing a SETCLIENTID_CONFIRM request to race with a confirmed client's expiration. If the race occurs, the system may attempt to use a reference to a client object that has already been freed. An attacker can exploit this via network-based NFS requests to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches (e.g., 6.1, 6.6, 6.10, 6.11).
Affected products
- Linux Linux Kernel versions prior to 6.14-rc1 (fixed in various stable branches)
- Siemens SIMATIC CN 4100 versions prior to V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later
Timeline
- 2025-06-04: other: Initial patch authored
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/22f45cedf281e6171817c8a3432c44d788c550e1
- https://git.kernel.org/stable/c/36e83eda90e0e4ac52f259f775b40b2841f8a0a3
- https://git.kernel.org/stable/c/3f252a73e81aa01660cb426735eab932e6182e8d
- https://git.kernel.org/stable/c/571a5e46c71490285d2d8c06f6b5a7cbf6c7edd1
- https://git.kernel.org/stable/c/74ad36ed60df561a303a19ecef400c7096b20306
- https://git.kernel.org/stable/c/908e4ead7f757504d8b345452730636e298cbf68
- https://git.kernel.org/stable/c/d35ac850410966010e92f401f4e21868a9ea4d8b