CVE-2025-21795

MEDIUM

Linux Kernel - Denial of Service via NFSD Callback Hang

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is not 0. This hang lasts about 15 minutes until TCP notifies NFSD that the connection was dropped. This patch modifies nfsd4_run_cb_work to skip the RPC call if nfs4_client is in courtesy state.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (26)
linux/Kernel < 5.10.235linux
linux/Kernel 5.11.0 - 5.15.179linux
linux/Kernel 5.16.0 - 6.1.129linux
linux/Kernel 5.19.0 - 6.6.79linux
linux/Kernel 6.2.0 - 6.12.16linux
linux/Kernel 6.7.0 - 6.13.4linux
Linux/Linux < 5.19
Linux/Linux 26540b8940a2e21582afa61a6fb8af87310bac72 - efa8a261c575f816c7e79a87aeb3ef8a0bd6b221
Linux/Linux 5.10.220 - 5.10.235
Linux/Linux 5.10.235 - 5.10.*
... and 16 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026