CVE-2025-38430

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38430
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38430.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38430
Downstream
Related
Published
2025-07-25T14:16:49.443Z
Modified
2025-11-28T02:34:46.519093Z
Summary
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: nfsd4spomust_allow() must check this is a v4 compound request

If the request being processed is not a v4 compound request, then examining the cstate can have undefined results.

This patch adds a check that the rpc procedure being executed (rqprocinfo) is the NFSPROC4COMPOUND procedure.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38430.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
bf78a2706ce975981eb5167f2d3b609eb5d24c19
Fixed
b1d0323a09a29f81572c7391e0d80d78724729c9
Fixed
425efc6b3292a3c79bfee4a1661cf043dcd9cf2f
Fixed
64a723b0281ecaa59d31aad73ef8e408a84cb603
Fixed
e7e943ddd1c6731812357a28e7954ade3a7d8517
Fixed
7a75a956692aa64211a9e95781af1ec461642de4
Fixed
2c54bd5a380ebf646fb9efbc4ae782ff3a83a5af
Fixed
1244f0b2c3cecd3f349a877006e67c9492b41807

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.295
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.142
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.95
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.35
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.4