{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-40210", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T07:20:57.179Z", "datePublished": "2025-11-21T10:21:35.540Z", "dateUpdated": "2026-08-05T12:08:36.344Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:08:36.344Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"NFSD: Remove the cap on number of operations per NFSv4 COMPOUND\"\n\nI've found that pynfs COMP6 now leaves the connection or lease in a\nstrange state, which causes CLOSE9 to hang indefinitely. I've dug\ninto it a little, but I haven't been able to root-cause it yet.\nHowever, I bisected to commit 48aab1606fa8 (\"NFSD: Remove the cap on\nnumber of operations per NFSv4 COMPOUND\").\n\nTianshuo Han also reports a potential vulnerability when decoding\nan NFSv4 COMPOUND. An attacker can place an arbitrarily large op\ncount in the COMPOUND header, which results in:\n\n[ 51.410584] nfsd: vmalloc error: size 1209533382144, exceeds total\npages, mode:0xdc0(GFP_KERNEL|__GFP_ZERO),\nnodemask=(null),cpuset=/,mems_allowed=0\n\nwhen NFSD attempts to allocate the COMPOUND op array.\n\nLet's restore the operation-per-COMPOUND limit, but increased to 200\nfor now." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The vulnerable code is the NFSv4 COMPOUND XDR decoder in the in-kernel NFS server, driven directly by bytes received on TCP/UDP port 2049 from a remote client. No local access is needed.\nAC:L - A single malformed COMPOUND header with a large 32-bit op count deterministically triggers the unbounded vcalloc; the attacker fully controls the requested size and can tune it to either fail loudly or succeed and pin gigabytes.\nPR:N - The allocation occurs during XDR decode, before any export, filehandle, or file-permission check, and the only gate is `svc_set_client`'s IP-based export ACL — not a user credential. Under the standard AUTH_SYS flavor no secret or account on the server is required.\nUI:N - The attacker only needs to send an RPC to the listening nfsd port; no action by any local user or administrator is involved.\nS:U - The impact is confined to the NFS server kernel's own memory and scheduling resources, with no crossing into another security authority such as a hypervisor or IOMMU boundary.\nC:N - `size_mul()` saturates instead of wrapping, so the array is never undersized; there is no out-of-bounds read, no uninitialized memory exposure, and nothing is returned to the attacker beyond a garbage-args RPC error.\nI:N - No attacker-controlled data is written outside the correctly sized allocation and no filesystem or kernel state is modified — the request is rejected once decode fails.\nA:H - An unauthenticated remote client can force arbitrarily large `GFP_KERNEL|__GFP_ZERO` vmalloc requests, exhausting kernel memory and triggering OOM kills, reclaim stalls and allocation-failure splats across all nfsd threads; the same regression also produces the reported indefinite CLOSE hang." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfsd/nfs4proc.c", "fs/nfsd/nfs4state.c", "fs/nfsd/nfs4xdr.c", "fs/nfsd/nfsd.h", "fs/nfsd/xdr4.h" ], "versions": [ { "version": "48aab1606fa80027143a445224f552b4eeea845b", "lessThan": "b3ee7ce432289deac87b9d14e01f2fe6958f7f0b", "status": "affected", "versionType": "git" }, { "version": "48aab1606fa80027143a445224f552b4eeea845b", "lessThan": "3e7f011c255582d7c914133785bbba1990441713", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfsd/nfs4proc.c", "fs/nfsd/nfs4state.c", "fs/nfsd/nfs4xdr.c", "fs/nfsd/nfsd.h", "fs/nfsd/xdr4.h" ], "versions": [ { "version": "6.17", "status": "affected" }, { "version": "0", "lessThan": "6.17", "status": "unaffected", "versionType": "semver" }, { "version": "6.17.8", "lessThanOrEqual": "6.17.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.17", "versionEndExcluding": "6.17.8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.17", "versionEndExcluding": "6.18" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/b3ee7ce432289deac87b9d14e01f2fe6958f7f0b" }, { "url": "https://git.kernel.org/stable/c/3e7f011c255582d7c914133785bbba1990441713" } ], "title": "Revert \"NFSD: Remove the cap on number of operations per NFSv4 COMPOUND\"", "x_generator": { "engine": "bippy-1.2.0" } } } }