Database/Control plane, storage & DevOps
Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive the
CVE-2025-40212Control plane, storage & DevOpscurated
Impact
A refcount leak in the pseudo-root filehandle path lets a client drive the reference count until state is mishandled, giving remote memory corruption on the server. Reached through ordinary NFSv4 LOOKUP traversal of the exported pseudo-filesystem.
Who can reach it
Any NFSv4 client that can reach the server and walk the export pseudo-root.
What to do
Update the storage server kernel and reboot. This is in the standard NFSv4 lookup path, so there is no export-level mitigation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.