Junglewise Threat Intelligence

CVE-2025-39798: Linux Kernel NFS capability inheritance flaw in automounting

CVE-2025-39798 · Severity: high · CVSS 7.3 · Published 2025-09-12

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's Network File System (NFS) component could allow incorrect security settings to be applied when automatically mounting new network drives. This occurs because the system fails to properly reset and re-verify security capabilities when moving between different filesystems. In practice, this could lead to unauthorized data access or minor system instability on affected devices, including certain industrial control systems.

Technical details

A vulnerability exists in the Linux kernel NFS client where capabilities are incorrectly inherited when crossing into a new filesystem via automounting. The root cause is located in 'fs/nfs/client.c' and 'fs/nfs/nfs4client.c', where the system failed to reset capabilities to minimal defaults before probing the new filesystem. An attacker could potentially leverage this misconfiguration to bypass intended security constraints or cause a denial of service. The issue affects multiple stable kernel branches and has been addressed by introducing 'nfs_server_set_init_caps' to ensure capabilities are properly initialized during server cloning and initialization. Patches are available for major LTS kernel versions.

Affected products

  • Linux Linux Kernel 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y, 6.11.y, 6.12.y
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5

Timeline

  • 2025-08-03: other: Initial patch authored by Trond Myklebust
  • 2025-08-28: patched: Patch committed to Linux stable tree
  • 2025-09-12: disclosed: CVE published

References

Related threats