← All CVEs

CVE-2025-38430

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

9.8
CVSS
0.5%
EPSS (exploit prob.)
42nd
EPSS percentile
2025-07-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
linuxlinux_kernel< 5.4.295
linuxlinux_kernel>= 5.5, < 5.10.239
linuxlinux_kernel>= 5.11, < 5.15.186
linuxlinux_kernel>= 5.16, < 6.1.142
linuxlinux_kernel>= 6.2, < 6.6.95
linuxlinux_kernel>= 6.7, < 6.12.35
linuxlinux_kernel>= 6.13, < 6.15.4
debiandebian_linux11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-38430