Junglewise Threat Intelligence

CVE-2025-38724: Linux Kernel nfsd use-after-free in nfsd4_setclientid_confirm

CVE-2025-38724 · Severity: critical · CVSS 9.8 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's Network File System (NFS) server component, which is used to share files across a network. A flaw in how the server handles client identification requests can lead to a system crash or allow unauthorized access to memory. This could result in a complete service outage or the theft of sensitive data stored on the server.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's NFSD (NFS server) implementation within the nfsd4_setclientid_confirm() function. The root cause is a failure to check the return value of get_client_locked(), allowing a SETCLIENTID_CONFIRM request to race with a confirmed client's expiration. If the race occurs, the system may attempt to use a reference to a client object that has already been freed. An attacker can exploit this via network-based NFS requests to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. Patches have been released across multiple stable kernel branches (e.g., 6.1, 6.6, 6.10, 6.11).

Affected products

  • Linux Linux Kernel versions prior to 6.14-rc1 (fixed in various stable branches)
  • Siemens SIMATIC CN 4100 versions prior to V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later

Timeline

  • 2025-06-04: other: Initial patch authored
  • 2025-09-04: disclosed: CVE published

References

Related threats