PT-2025-35997 · Linux +1 · Linux Kernel +1
Lei Lu
·
Published
2025-09-04
·
Updated
2025-09-04
·
CVE-2025-38724
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The `nfsd4 setclientid confirm()` function did not check the return value from `get client locked()`. A `SETCLIENTID CONFIRM` operation could race with a confirmed client expiring, failing to obtain a reference, and potentially leading to a use-after-free (UAF) condition. The issue was addressed by obtaining a reference early in the case of an existing confirmed client and handling failures appropriately.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Related Identifiers
CVE-2025-38724
Affected Products
Debian
Linux Kernel
References · 15
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-38724 · Security Note
- https://security-tracker.debian.org/tracker/source-package/linux · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-38724 · Security Note
- https://security-tracker.debian.org/tracker/CVE-2025-38724 · Vendor Advisory
- https://git.kernel.org/stable/c/22f45cedf281e6171817c8a3432c44d788c550e1 · Note
- https://packages.debian.org/src:linux · Note
- https://twitter.com/CVEnew/status/1963637904733081789 · Twitter Post
- https://git.kernel.org/stable/c/74ad36ed60df561a303a19ecef400c7096b20306 · Note
- https://git.kernel.org/stable/c/d71abd1ae4e0413707cd42b10c24a11d1aa71772 · Note
- https://git.kernel.org/stable/c/908e4ead7f757504d8b345452730636e298cbf68 · Note
- https://git.kernel.org/stable/c/3f252a73e81aa01660cb426735eab932e6182e8d · Note
- https://git.kernel.org/stable/c/d35ac850410966010e92f401f4e21868a9ea4d8b · Note
- https://git.kernel.org/stable/c/36e83eda90e0e4ac52f259f775b40b2841f8a0a3 · Note
- https://git.kernel.org/stable/c/f3aac6cf390d8b80e1d82975faf4ac61175519c0 · Note
- https://git.kernel.org/stable/c/571a5e46c71490285d2d8c06f6b5a7cbf6c7edd1 · Note