Database/Control plane, storage & DevOps
Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive the
CVSS 9.8CVE-2025-40212Control plane, storage & DevOpscurated
Impact
A refcount leak in the pseudo-root filehandle path lets a client drive the reference count until state is mishandled, giving remote memory corruption on the server. Reached through ordinary NFSv4 LOOKUP traversal of the exported pseudo-filesystem.
Who can reach it
Any NFSv4 client that can reach the server and walk the export pseudo-root.
What to do
Update the storage server kernel and reboot. This is in the standard NFSv4 lookup path, so there is no export-level mitigation.
References
Related entries
- Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCVE-2025-41426 · Vertiv (stack-based buffer overflow, code execution)Critical
- Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCVE-2025-46412 · Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cardsCritical
- Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CVE-2025-49825 · TeleportCritical
- F5 BIG-IP (APM access policy): Specific malicious traffic against a virtual server with a BIG-IP APM access policyCVE-2025-53521 · F5 BIG-IP (APM access policy)Critical
- Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server): A memoryCVE-2025-6543 · Citrix NetScaler ADC / Gateway (configured as VPN Gateway, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server)Critical
- Lantronix EDS5000 serial-to-Ethernet device server: Root command execution on the device serverCVE-2025-67038 · Lantronix EDS5000 serial-to-Ethernet device serverCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.