Junglewise Threat Intelligence

CVE-2025-40210: Linux Kernel NFSD denial of service in NFSv4 COMPOUND decoding

CVE-2025-40210 · Severity: high · CVSS 7.5 · Published 2025-11-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Network File System (NFS) server could allow a remote attacker to crash the system. By sending a specially crafted request with an excessively large number of operations, an attacker can trigger a memory allocation failure in the server. This results in a denial-of-service condition, potentially disrupting file sharing services and impacting business operations that rely on networked storage.

Technical details

The vulnerability exists in the NFS server (NFSD) component of the Linux kernel when decoding NFSv4 COMPOUND requests. A previous change (commit 48aab1606fa8) removed the cap on the number of operations allowed per COMPOUND request. An attacker can provide an arbitrarily large operation count in the COMPOUND header, causing the kernel to attempt a massive memory allocation via vcalloc() for the operation array. This leads to a vmalloc error and potential system instability or denial-of-service. The fix restores a limit (NFSD_MAX_OPS_PER_COMPOUND) set to 200 operations. The issue was resolved in stable kernels 6.17.8 and the 6.18 development cycle.

Affected products

  • Linux Linux Kernel 6.17 to 6.17.7, 6.18-rc1 to 6.18-rcX

Timeline

  • 2025-10-02: patched: Initial fix commit authored
  • 2025-11-21: disclosed: CVE published

References

Related threats