PT-2025-28007 · Linux+5 · Linux Kernel+5

CVE-2025-38232

·

Publicado

2025-03-06

·

Atualizado

2026-05-26

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to the fixed version
Description: A race condition exists between nfsd registration and exports proc, which can cause a kernel OOPs. This issue is triggered by a race between the exportfs -r command and the mount -t nfsd none /proc/fs/nfsd command. The estimated number of potentially affected devices is not specified. Technical details about exploitation include the exports net open() function and the cache seq next rcu() function. The issue can be reproduced using a script that continuously runs the exportfs -r command and mounts and unmounts the nfsd filesystem.
Recommendations: For Linux kernel versions prior to the fixed version: update to a version that includes the fix for the NFSD race condition between nfsd registration and exports proc. As a temporary workaround, consider disabling the nfsd module until a patch is available. Restrict access to the /proc/fs/nfsd filesystem to minimize the risk of exploitation. Avoid using the exportfs -r command and the mount -t nfsd none /proc/fs/nfsd command simultaneously until the issue is resolved.

Exploit

Correção

DoS

NULL Pointer Dereference

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-70427
BDU:2025-09033
CVE-2025-38232
ECHO-6989-D1A9-E5BC
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2026:20560-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1
USN-8162-1
USN-8180-1
USN-8180-2
USN-8180-3
USN-8180-4
USN-8180-5
USN-8180-6
USN-8186-1
USN-8187-1
USN-8188-1
USN-8243-1
USN-8275-1
USN-8297-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu