CVE-2025-38430

Updated: 2025-12-28 03:53:55.466925

Description:

In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-12-28 08:10:08
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2026-01-17 01:05:37 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:35 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:36 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:37 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:33 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:32 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2026-01-17 01:05:34 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:33 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:19:37 This flaw is confined to the kernel NFS server (nfsd) path and is reachable only on hosts actively s...
Total: 16