CVE-2025-21900

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21900
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21900.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21900
Downstream
Related
Published
2025-04-01T15:26:51Z
Modified
2025-10-17T22:20:11.937160Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
NFSv4: Fix a deadlock when recovering state on a sillyrenamed file
Details

In the Linux kernel, the following vulnerability has been resolved:

NFSv4: Fix a deadlock when recovering state on a sillyrenamed file

If the file is sillyrenamed, and slated for delete on close, it is possible for a server reboot to triggeer an open reclaim, with can again race with the application call to close(). When that happens, the call to putnfsopen_context() can trigger a synchronous delegreturn call which deadlocks because it is not marked as privileged.

Instead, ensure that the call to nfs4inodereturndelegationon_close() catches the delegreturn, and schedules it asynchronously.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
adb4b42d19aea91826621a8d0bac94cf2c08f8bc
Fixed
4fe4ae6c2e01d028856b73b6328b12b8945df871
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
adb4b42d19aea91826621a8d0bac94cf2c08f8bc
Fixed
f41a60bc43e7abbc636fee78bed0d74c31e738b0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
adb4b42d19aea91826621a8d0bac94cf2c08f8bc
Fixed
8f8df955f078e1a023ee55161935000a67651f38

Affected versions

v6.*

v6.10
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1
v6.12.10
v6.12.11
v6.12.12
v6.12.13
v6.12.14
v6.12.15
v6.12.16
v6.12.17
v6.12.2
v6.12.3
v6.12.4
v6.12.5
v6.12.6
v6.12.7
v6.12.8
v6.12.9
v6.13
v6.13-rc1
v6.13-rc2
v6.13-rc3
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.13-rc7
v6.13.1
v6.13.2
v6.13.3
v6.13.4
v6.13.5
v6.14-rc1
v6.14-rc2
v6.14-rc3

Database specific

vanir_signatures

[
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8df955f078e1a023ee55161935000a67651f38",
        "signature_type": "Line",
        "id": "CVE-2025-21900-01263022",
        "target": {
            "file": "fs/nfs/nfs4proc.c"
        },
        "digest": {
            "line_hashes": [
                "29145696395206778794204689170876650461",
                "27698307694998991446359545296086507873",
                "20546435871902220924091620689248240760",
                "89904501461873493309785125405833074856",
                "88665879663643343103791485039377433756",
                "15845749876373813610876543492652395553"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f41a60bc43e7abbc636fee78bed0d74c31e738b0",
        "signature_type": "Line",
        "id": "CVE-2025-21900-2c4434dd",
        "target": {
            "file": "fs/nfs/nfs4proc.c"
        },
        "digest": {
            "line_hashes": [
                "29145696395206778794204689170876650461",
                "27698307694998991446359545296086507873",
                "20546435871902220924091620689248240760",
                "89904501461873493309785125405833074856",
                "88665879663643343103791485039377433756",
                "15845749876373813610876543492652395553"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8df955f078e1a023ee55161935000a67651f38",
        "signature_type": "Line",
        "id": "CVE-2025-21900-3e1ddca9",
        "target": {
            "file": "fs/nfs/delegation.h"
        },
        "digest": {
            "line_hashes": [
                "310205952638494554185545030407186354531",
                "69489486017284981805661451716488517888",
                "327217013223093950629239117805550239443",
                "4886013556343620346162745297065122676"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4fe4ae6c2e01d028856b73b6328b12b8945df871",
        "signature_type": "Line",
        "id": "CVE-2025-21900-4ad04ba2",
        "target": {
            "file": "fs/nfs/delegation.h"
        },
        "digest": {
            "line_hashes": [
                "310205952638494554185545030407186354531",
                "69489486017284981805661451716488517888",
                "327217013223093950629239117805550239443",
                "4886013556343620346162745297065122676"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f41a60bc43e7abbc636fee78bed0d74c31e738b0",
        "signature_type": "Function",
        "id": "CVE-2025-21900-6ef28281",
        "target": {
            "file": "fs/nfs/nfs4proc.c",
            "function": "nfs4_close_context"
        },
        "digest": {
            "length": 216.0,
            "function_hash": "54641124595122351361032175226350042028"
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4fe4ae6c2e01d028856b73b6328b12b8945df871",
        "signature_type": "Line",
        "id": "CVE-2025-21900-7cfe433f",
        "target": {
            "file": "fs/nfs/nfs4proc.c"
        },
        "digest": {
            "line_hashes": [
                "29145696395206778794204689170876650461",
                "27698307694998991446359545296086507873",
                "20546435871902220924091620689248240760",
                "89904501461873493309785125405833074856",
                "88665879663643343103791485039377433756",
                "15845749876373813610876543492652395553"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8df955f078e1a023ee55161935000a67651f38",
        "signature_type": "Function",
        "id": "CVE-2025-21900-8ab887be",
        "target": {
            "file": "fs/nfs/nfs4proc.c",
            "function": "nfs4_close_context"
        },
        "digest": {
            "length": 216.0,
            "function_hash": "54641124595122351361032175226350042028"
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f41a60bc43e7abbc636fee78bed0d74c31e738b0",
        "signature_type": "Line",
        "id": "CVE-2025-21900-8cc21ee3",
        "target": {
            "file": "fs/nfs/delegation.c"
        },
        "digest": {
            "line_hashes": [
                "6063764780445749735333617246258701133",
                "181040685335472011927542828217583073111",
                "155667187020879516956922329726509519796"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4fe4ae6c2e01d028856b73b6328b12b8945df871",
        "signature_type": "Function",
        "id": "CVE-2025-21900-8f3a6f4d",
        "target": {
            "file": "fs/nfs/nfs4proc.c",
            "function": "nfs4_close_context"
        },
        "digest": {
            "length": 216.0,
            "function_hash": "54641124595122351361032175226350042028"
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8df955f078e1a023ee55161935000a67651f38",
        "signature_type": "Line",
        "id": "CVE-2025-21900-d2209f74",
        "target": {
            "file": "fs/nfs/delegation.c"
        },
        "digest": {
            "line_hashes": [
                "6063764780445749735333617246258701133",
                "181040685335472011927542828217583073111",
                "155667187020879516956922329726509519796"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4fe4ae6c2e01d028856b73b6328b12b8945df871",
        "signature_type": "Line",
        "id": "CVE-2025-21900-d6e08645",
        "target": {
            "file": "fs/nfs/delegation.c"
        },
        "digest": {
            "line_hashes": [
                "6063764780445749735333617246258701133",
                "181040685335472011927542828217583073111",
                "155667187020879516956922329726509519796"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f41a60bc43e7abbc636fee78bed0d74c31e738b0",
        "signature_type": "Line",
        "id": "CVE-2025-21900-e9169477",
        "target": {
            "file": "fs/nfs/delegation.h"
        },
        "digest": {
            "line_hashes": [
                "310205952638494554185545030407186354531",
                "69489486017284981805661451716488517888",
                "327217013223093950629239117805550239443",
                "4886013556343620346162745297065122676"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1"
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.18
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.6