CVE-2025-21795
27.02.2025, 03:15
In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is not 0. This hang lasts about 15 minutes until TCP notifies NFSD that the connection was dropped. This patch modifies nfsd4_run_cb_work to skip the RPC call if nfs4_client is in courtesy state.Enginsight
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 5.10.220 ≤ 𝑥 < 5.10.235 |
| linux | linux_kernel | 5.15.154 ≤ 𝑥 < 5.15.179 |
| linux | linux_kernel | 5.19 ≤ 𝑥 < 6.1.129 |
| linux | linux_kernel | 6.2 ≤ 𝑥 < 6.6.79 |
| linux | linux_kernel | 6.7 ≤ 𝑥 < 6.12.16 |
| linux | linux_kernel | 6.13 ≤ 𝑥 < 6.13.4 |
| linux | linux_kernel | 6.14:rc1 |
| linux | linux_kernel | 6.14:rc2 |
𝑥
= Vulnerable software versions
Debian Releases
References