Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

nvd Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2025-38430

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 25 июл. 2025
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: nvd
CVSS3: 9.8
CVSS3: 5.5
EPSS Низкий

ОписаниС

In the Linux kernel, the following vulnerability has been resolved:

nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request

If the request being processed is not a v4 compound request, then examining the cstate can have undefined results.

This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

УязвимыС ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΠΈ

ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΡ 1

Одно из

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия Π΄ΠΎ 5.4.295 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 5.5 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 5.10.239 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 5.11 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 5.15.186 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 5.16 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 6.1.142 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 6.2 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 6.6.95 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 6.7 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 6.12.35 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 6.13 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 6.15.4 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΡ 2
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 40%
0.00491
Низкий

9.8 Critical

CVSS3

5.5 Medium

CVSS3

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

NVD-CWE-noinfo

БвязанныС уязвимости

CVSS3: 9.8
ubuntu
ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

CVSS3: 5.5
redhat
ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

CVSS3: 7.1
msrc
12 мСсяцСв Π½Π°Π·Π°Π΄

nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request

CVSS3: 9.8
debian
ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

In the Linux kernel, the following vulnerability has been resolved: n ...

CVSS3: 5.5
github
ΠΎΠΊΠΎΠ»ΠΎ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This patch adds a check that the rpc procedure being executed (rq_procinfo) is the NFSPROC4_COMPOUND procedure.

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 40%
0.00491
Низкий

9.8 Critical

CVSS3

5.5 Medium

CVSS3

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

NVD-CWE-noinfo
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2025-38430