PT-2025-16664 · Linux+4 · Linux Kernel+4

Published

2025-03-10

·

Updated

2026-01-21

·

CVE-2025-22024

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc6+
Description A vulnerability in the Linux kernel has been resolved, related to the management of listener transports in the nfsd module. When no active threads are running, a root user using the nfsdctl command can try to remove a particular listener from the list of previously added ones, then start the server by increasing the number of threads, leading to a use-after-free issue. The vulnerability is caused by the nfsd nl listener set doit() function manipulating the list of transports of the server's sv permsocks and closing the specified listener, but not updating the other list of transports (server's sp xprts list).
Recommendations To resolve the issue, update the Linux kernel to a version newer than 6.13.0-rc6+. As a temporary workaround, consider restricting access to the nfsdctl command to prevent exploitation. Additionally, avoid using the nfsdctl command to remove listeners when no active threads are running, as this can trigger the vulnerability.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12098
CVE-2025-22024
USN-7594-1
USN-7594-2
USN-7594-3
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu