CVE-2025-38724: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
Published Sep 4, 2025
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Other sources
nfsd: handle getclientlocked() failure in nfsd4setclientidconfirm()
— Microsoft
Affected Software
16 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel>=3.17<5.4.297
Linux Linux kernel>=5.5<5.10.241
Linux Linux kernel>=5.11<5.15.190
Linux Linux kernel>=5.16<6.1.149
Linux Linux kernel>=6.2<6.6.103
Linux Linux kernel>=6.7<6.12.43
Linux Linux kernel>=6.13<6.15.11
Linux Linux kernel>=6.16<6.16.2
Debian Debian Linux=11.0
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.11.35.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.25.0
debian/linux
6.1.176-16.1.187-16.12.107-16.12.111-17.2.6-17.2.8-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 6.12.111-1Fixed in 7.2.6-1Fixed in 7.2.8-1
Event History
Sep 4, 2025
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionSeverity
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2025
Data Sourced
via Microsoft·01:08 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:08 AM
SeverityAffected Software
Updated
via Microsoft·08:08 AM
SeverityAffected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity
Aug 19, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 26, 2026
Data Sourced
via Launchpad·11:26 AM
Description
Sep 29, 2026
Data Sourced
via Debian·11:28 AM
DescriptionAffected Software
Oct 1, 2026
Data Sourced
via Ubuntu·11:28 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38724?
CVE-2025-38724 has a medium severity rating due to its potential impact on the NFS server's stability.
2
How do I fix CVE-2025-38724?
To mitigate CVE-2025-38724, update your Linux kernel to the latest version where this vulnerability has been patched.
3
What systems are affected by CVE-2025-38724?
CVE-2025-38724 affects various versions of the Linux kernel that implement NFS services.
4
Is CVE-2025-38724 remotely exploitable?
CVE-2025-38724 is considered potentially exploitable remotely, depending on the NFS configuration.
5
Who reported CVE-2025-38724?
CVE-2025-38724 was reported by researcher Lei Lu.