CVE-2025-38566: sunrpc: fix handling of server side tls alerts

Published Aug 19, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: fix handling of server side tls alerts

Scott Mayhew discovered a security exploit in NFS over TLS in tlsalertrecv() due to its assumption it can read data from the msg iterator's kvec..

kTLS implementation splits TLS non-data record payload between the control message buffer (which includes the type such as TLS aler or TLS cipher change) and the rest of the payload (say TLS alert's level/description) which goes into the msg payload buffer.

This patch proposes to rework how control messages are setup and used by sockrecvmsg().

If no control message structure is setup, kTLS layer will read and process TLS data record types. As soon as it encounters a TLS control message, it would return an error. At that point, NFS can setup a kvec backed msg buffer and read in the control message such as a TLS alert. Msg iterator can advance the kvec pointer as a part of the copy process thus we need to revert the iterator before calling into the tlsalertrecv.

Affected Software

6 affected components
Linux Kernel
Linux Linux kernel>=6.4<6.6.102
Linux Linux kernel>=6.7<6.12.42
Linux Linux kernel>=6.13<6.15.10
Linux Linux kernel>=6.16<6.16.1
Linux Linux kernel=6.17-rc1

Event History

Aug 19, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:03 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-38566?

CVE-2025-38566 has been classified with a medium severity level due to its potential impact on the confidentiality and integrity of NFS over TLS communications.

2

How do I fix CVE-2025-38566?

To remediate CVE-2025-38566, it is recommended to upgrade to the latest version of the Linux kernel where the vulnerability has been patched.

3

Which versions of the Linux kernel are affected by CVE-2025-38566?

CVE-2025-38566 affects several versions of the Linux kernel that support NFS over TLS prior to the fix being applied.

4

What are the implications of CVE-2025-38566 for NFS over TLS?

The implications of CVE-2025-38566 include potential exposure to security alerts that could be mishandled, leading to data exposure.

5

Who discovered the CVE-2025-38566 vulnerability?

CVE-2025-38566 was discovered by Scott Mayhew, highlighting issues with the server side TLS alerts in NFS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203