cbcvebase.
CVE-2025-38566
published 2025-08-19

CVE-2025-38566: In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.59%
44.7th percentile
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's kvec.. kTLS implementation splits TLS non-data record payload between the control message buffer (which includes the type such as TLS aler or TLS cipher change) and the rest of the payload (say TLS alert's level/description) which goes into the msg payload buffer. This patch proposes to rework how control messages are setup and used by sock_recvmsg(). If no control message structure is setup, kTLS layer will read and process TLS data record types. As soon as it encounters a TLS control message, it would return an error. At that point, NFS can setup a kvec backed msg buffer and read in the control message such as a TLS alert. Msg iterator can advance the kvec pointer as a part of the copy process thus we need to revert the iterator before calling into the tls_alert_recv.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 5e052dda121e2870dd87181783da4a95d7d2927b < b1df394621710b312f0393e3f240fdac0764f968b1df394621710b312f0393e3f240fdac0764f968
linuxlinux>= 5e052dda121e2870dd87181783da4a95d7d2927b < 25bb3647d30a20486b5fe7cff2b0e503c16c969225bb3647d30a20486b5fe7cff2b0e503c16c9692
linuxlinux>= 5e052dda121e2870dd87181783da4a95d7d2927b < 3b549da875414989f480b66835d514be80a0bd9c3b549da875414989f480b66835d514be80a0bd9c
linuxlinux>= 5e052dda121e2870dd87181783da4a95d7d2927b < 6b33c31cc788073bfbed9297e1f4486ed73d87da6b33c31cc788073bfbed9297e1f4486ed73d87da
linuxlinux>= 5e052dda121e2870dd87181783da4a95d7d2927b < bee47cb026e762841f3faece47b51f985e215edbbee47cb026e762841f3faece47b51f985e215edb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.15.106.15.10
linuxlinux_kernel>= 6.16 < 6.16.16.16.1
linuxlinux_kernel>= 6.4 < 6.6.1026.6.102
linuxlinux_kernel>= 6.7 < 6.12.426.12.42
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_msrc5.8MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.