GPU VulnDB

Database/Control plane, storage & DevOps

Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without first

CVE-2025-38430Control plane, storage & DevOpscurated

Impact

nfsd4_spo_must_allow examines NFSv4 compound state without first checking the request actually is a v4 compound, so a non-compound request drives it into invalid memory. Remote, unauthenticated, and it crashes or corrupts the file server every tenant depends on.

Who can reach it

Any host that can send RPC to the nfsd port. No mount or credential required.

What to do

Update the storage server kernel to a release with the fix and reboot. Restrict which subnets can reach port 2049 in the interim - it does not eliminate the bug but it reduces who can send the malformed request.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.