cbcvebase.
CVE-2025-38430
published 2025-07-25

CVE-2025-38430: In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < bf78a2706ce975981eb5167f2d3b609eb5d24c19bf78a2706ce975981eb5167f2d3b609eb5d24c19
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < b1d0323a09a29f81572c7391e0d80d78724729c9b1d0323a09a29f81572c7391e0d80d78724729c9
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < 425efc6b3292a3c79bfee4a1661cf043dcd9cf2f425efc6b3292a3c79bfee4a1661cf043dcd9cf2f
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < 64a723b0281ecaa59d31aad73ef8e408a84cb60364a723b0281ecaa59d31aad73ef8e408a84cb603
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < e7e943ddd1c6731812357a28e7954ade3a7d8517e7e943ddd1c6731812357a28e7954ade3a7d8517
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < 7a75a956692aa64211a9e95781af1ec461642de47a75a956692aa64211a9e95781af1ec461642de4
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < 2c54bd5a380ebf646fb9efbc4ae782ff3a83a5af2c54bd5a380ebf646fb9efbc4ae782ff3a83a5af
linuxlinux>= ed94164398c935a42be7b129a478eb19c598b68a < 1244f0b2c3cecd3f349a877006e67c9492b418071244f0b2c3cecd3f349a877006e67c9492b41807
linuxlinux_kernel< 5.4.2955.4.295
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1865.15.186
linuxlinux_kernel>= 5.16 < 6.1.1426.1.142
linuxlinux_kernel>= 5.5 < 5.10.2395.10.239
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.2 < 6.6.956.6.95
linuxlinux_kernel>= 6.7 < 6.12.356.12.35

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM