cbcvebase.
CVE-2025-39688
published 2025-04-18

CVE-2025-39688: In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.56%
43.7th percentile
In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then tries to use the deleg stateid and expects to see NFS4ERR_DELEG_REVOKED, but it gets bad NFS4ERR_BAD_STATEID instead. When a delegation is revoked, it's initially marked with SC_STATUS_REVOKED, or SC_STATUS_ADMIN_REVOKED and later, it's marked with the SC_STATUS_FREEABLE flag, which denotes that it is waiting for s FREE_STATEID call. nfs4_lookup_stateid() accepts a statusmask that includes the status flags that a found stateid is allowed to have. Currently, that mask never includes SC_STATUS_FREEABLE, which means that revoked delegations are (almost) never found. Add SC_STATUS_FREEABLE to the always-allowed status flags, and remove it from nfsd4_delegreturn() since it's now always implied.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.11.6 < 6.126.12
linuxlinux>= 8dd91e8d31febf4d9cca3ae1bb4771d33ae7ee5a < 52e209203c35a4fbff8af23cd3613efe5df4010252e209203c35a4fbff8af23cd3613efe5df40102
linuxlinux>= 8dd91e8d31febf4d9cca3ae1bb4771d33ae7ee5a < dc6f3295905d7185e71091870119a8c11c3808ccdc6f3295905d7185e71091870119a8c11c3808cc
linuxlinux>= 8dd91e8d31febf4d9cca3ae1bb4771d33ae7ee5a < 5bcb44e650bc4ec7eac23df90c5e011a77fa2beb5bcb44e650bc4ec7eac23df90c5e011a77fa2beb
linuxlinux>= 8dd91e8d31febf4d9cca3ae1bb4771d33ae7ee5a < d1bc15b147d35b4cb7ca99a9a7d79d41ca342c13d1bc15b147d35b4cb7ca99a9a7d79d41ca342c13
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.11.6 < 6.126.12
linuxlinux_kernel>= 6.12.1 < 6.12.236.12.23
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.