#VU114967 Input validation error in Linux kernel - CVE-2025-39730
Published: September 8, 2025
Vulnerability identifier: #VU114967
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-39730
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the nfs_fh_to_dentry() function in fs/nfs/export.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/12ad3def2e5e0b120e3d0cb6ce8b7b796819ad40
- https://git.kernel.org/stable/c/2ad40b7992aa26bc631afc1a995b0e3ddc30de3f
- https://git.kernel.org/stable/c/3570ef5c31314c13274c935a20b91768ab5bf412
- https://git.kernel.org/stable/c/763810bb883cb4de412a72f338d80947d97df67b
- https://git.kernel.org/stable/c/7dd36f7477d1e03a1fcf8d13531ca326c4fb599f
- https://git.kernel.org/stable/c/7f8eca87fef7519e9c41f3258f25ebc2752247ee
- https://git.kernel.org/stable/c/b7f7866932466332a2528fda099000b035303485
- https://git.kernel.org/stable/c/cb09afa0948d96b1e385d609ed044bb1aa043536
- https://git.kernel.org/stable/c/ef93a685e01a281b5e2a25ce4e3428cf9371a205