SB20250908100 - Input validation error in Linux kernel nfs
Published: September 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-39730)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the nfs_fh_to_dentry() function in fs/nfs/export.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/12ad3def2e5e0b120e3d0cb6ce8b7b796819ad40
- https://git.kernel.org/stable/c/2ad40b7992aa26bc631afc1a995b0e3ddc30de3f
- https://git.kernel.org/stable/c/3570ef5c31314c13274c935a20b91768ab5bf412
- https://git.kernel.org/stable/c/763810bb883cb4de412a72f338d80947d97df67b
- https://git.kernel.org/stable/c/7dd36f7477d1e03a1fcf8d13531ca326c4fb599f
- https://git.kernel.org/stable/c/7f8eca87fef7519e9c41f3258f25ebc2752247ee
- https://git.kernel.org/stable/c/b7f7866932466332a2528fda099000b035303485
- https://git.kernel.org/stable/c/cb09afa0948d96b1e385d609ed044bb1aa043536
- https://git.kernel.org/stable/c/ef93a685e01a281b5e2a25ce4e3428cf9371a205