CVE-2025-40210 — Allocation of Resources Without Limits or Throttling in Linux
Severity
7.5HIGH
No vectorEPSS
0.0%
top 94.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"
I've found that pynfs COMP6 now leaves the connection or lease in a
strange state, which causes CLOSE9 to hang indefinitely. I've dug
into it a little, but I haven't been able to root-cause it yet.
However, I bisected to commit 48aab1606fa8 ("NFSD: Remove the cap on
number of operations per NFSv4 COMPOUND").
Tianshuo Han also reports a potential vulnerab…
Affected Packages6 packages
▶CVEListV5linux/linux48aab1606fa80027143a445224f552b4eeea845b — b3ee7ce432289deac87b9d14e01f2fe6958f7f0b+2