CVE-2025-40326 — Improper Validation of Specified Type of Input in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 89.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Define actions for the new time_deleg FATTR4 attributes
NFSv4 clients won't send legitimate GETATTR requests for these new
attributes because they are intended to be used only with CB_GETATTR
and SETATTR. But NFSD has to do something besides crashing if it
ever sees a GETATTR request that queries these attributes.
RFC 8881 Section 18.7.3 states:
> The server MUST return a value for each attribute that the client
> requ…
Affected Packages5 packages
▶CVEListV5linux/linux51c0d4f7e317d3cb4a3001e502bd8ca2d57f2a4b — d8f3f94dc950e7c62c96af432c26745885b0a18a+2