GPU VulnDB

Database/Control plane, storage & DevOps

Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive the

CVE-2025-40212Control plane, storage & DevOpscurated

Impact

A refcount leak in the pseudo-root filehandle path lets a client drive the reference count until state is mishandled, giving remote memory corruption on the server. Reached through ordinary NFSv4 LOOKUP traversal of the exported pseudo-filesystem.

Who can reach it

Any NFSv4 client that can reach the server and walk the export pseudo-root.

What to do

Update the storage server kernel and reboot. This is in the standard NFSv4 lookup path, so there is no export-level mitigation.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.