Junglewise Threat Intelligence

CVE-2025-40212: Linux Kernel nfsd use-after-free in nfsd_set_fh_dentry

CVE-2025-40212 · Severity: critical · CVSS 9.8 · Published 2025-11-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Network File System (NFS) server component. The issue occurs when the server incorrectly handles specific file requests from older versions of the NFS protocol (v2 and v3). An attacker could exploit this to cause a system crash or potentially gain unauthorized access to data, leading to a denial of service or data compromise.

Technical details

A reference count leak exists in nfsd_set_fh_dentry() within the Linux kernel's NFS server implementation. The vulnerability is triggered when an NFSv2 or NFSv3 client provides a filehandle belonging to the NFSv4 pseudo-root filesystem. While the function correctly identifies this as an error, it prematurely stores the export reference in 'struct svc_fh' before dropping it via exp_put(). Consequently, a subsequent call to fh_put() results in a double-drop of the reference count, leading to a use-after-free condition. This can be exploited by a remote attacker to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. The fix involves deferring the assignment of the dentry and export to the svc_fh structure until after all error checks have passed.

Affected products

  • Linux Linux Kernel 6.12, 6.17, 6.18

Timeline

  • 2025-11-24: advisory: NVD published date
  • 2025-11-24: patched: Fixes merged into stable branches

References

Related threats