{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-40129", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T07:20:57.170Z", "datePublished": "2025-11-12T10:23:21.327Z", "dateUpdated": "2026-08-05T12:07:58.258Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:07:58.258Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix null pointer dereference on zero-length checksum\n\nIn xdr_stream_decode_opaque_auth(), zero-length checksum.len causes\nchecksum.data to be set to NULL. This triggers a NPD when accessing\nchecksum.data in gss_krb5_verify_mic_v2(). This patch ensures that\nthe value of checksum.len is not less than XDR_UNIT." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The vulnerable code is the server-side RPCSEC_GSS verifier path in the kernel's SUNRPC server (used by nfsd on TCP/2049), parsing attacker-supplied XDR from a received RPC Call. No local access is needed — a crafted RPC packet reaches `svcauth_gss_accept()` → `svcauth_gss_verify_header()` directly.\nAC:L - The attacker deterministically triggers the bug by emitting a single RPC_AUTH_GSS Call with a zero-length verifier body; there is no race, no memory-layout dependency, and no state the attacker cannot influence. Kerberized NFS (CONFIG_SUNRPC_GSS with gssproxy/rpc.svcgssd) is a standard enterprise deployment, not a rare config.\nPR:N - `svcauth_gss_verify_header()` runs before any credential is verified — it is the code that performs the verification — and the only gate is an rsc-cache lookup on the GSS context handle, which is a monotonically increasing 64-bit counter starting at 1 (`gss_proxy_save_rsc()`) sent in cleartext on the wire in every RPCSEC_GSS request. An unauthenticated remote attacker can trivially enumerate or sniff a valid handle and then supply the malformed verifier.\nUI:N - The crash is triggered entirely by an inbound RPC message processed by the nfsd service thread. No administrator or client-side action is required.\nS:U - The fault occurs and takes effect within the kernel of the NFS server itself, with no crossing of a virtualization, IOMMU, or other security-authority boundary.\nC:N - The defect is a read of address 0 (`memcpy(&be16_ptr, NULL, 2)`); it faults immediately and returns no data to the attacker. No memory contents are disclosed and no pointer values are leaked over the wire.\nI:N - No attacker-controlled data is written anywhere — the NULL pointer is only dereferenced for reading, and the request is aborted by the oops. There is no corruption primitive and no authentication bypass (the MIC check itself still fails).\nA:H - The NULL dereference oopses the nfsd kernel thread — and panics the host outright where `panic_on_oops` is set — and can be replayed indefinitely to kill every service thread, denying NFS service entirely." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/sunrpc/auth_gss/svcauth_gss.c" ], "versions": [ { "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4", "lessThan": "81cec07d303186d0d8c623ef8b5ecd3b81e94cf6", "status": "affected", "versionType": "git" }, { "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4", "lessThan": "affc03d44921f493deaae1d33151e3067a6f9f8f", "status": "affected", "versionType": "git" }, { "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4", "lessThan": "ab9a70cd2386a0d70c164b0905dd66bc9af52e77", "status": "affected", "versionType": "git" }, { "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4", "lessThan": "6df164e29bd4e6505c5a2e0e5f1e1f6957a16a42", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/sunrpc/auth_gss/svcauth_gss.c" ], "versions": [ { "version": "6.3", "status": "affected" }, { "version": "0", "lessThan": "6.3", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.112", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.53", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.17.3", "lessThanOrEqual": "6.17.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.6.112" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.12.53" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.17.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.18" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/81cec07d303186d0d8c623ef8b5ecd3b81e94cf6" }, { "url": "https://git.kernel.org/stable/c/affc03d44921f493deaae1d33151e3067a6f9f8f" }, { "url": "https://git.kernel.org/stable/c/ab9a70cd2386a0d70c164b0905dd66bc9af52e77" }, { "url": "https://git.kernel.org/stable/c/6df164e29bd4e6505c5a2e0e5f1e1f6957a16a42" } ], "title": "sunrpc: fix null pointer dereference on zero-length checksum", "x_generator": { "engine": "bippy-1.2.0" } } } }