CVE-2025-40129 (GCVE-0-2025-40129)
Vulnerability from cvelistv5
Published
2025-11-12 10:23
Modified
2026-08-05 12:07
Summary
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix null pointer dereference on zero-length checksum In xdr_stream_decode_opaque_auth(), zero-length checksum.len causes checksum.data to be set to NULL. This triggers a NPD when accessing checksum.data in gss_krb5_verify_mic_v2(). This patch ensures that the value of checksum.len is not less than XDR_UNIT.
Impacted products
Vendor Product Version
Linux Linux Version: 0653028e8f1c97fec30710813a001ad8a2ec34f4
Version: 0653028e8f1c97fec30710813a001ad8a2ec34f4
Version: 0653028e8f1c97fec30710813a001ad8a2ec34f4
Version: 0653028e8f1c97fec30710813a001ad8a2ec34f4
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/auth_gss/svcauth_gss.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "81cec07d303186d0d8c623ef8b5ecd3b81e94cf6",
              "status": "affected",
              "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4",
              "versionType": "git"
            },
            {
              "lessThan": "affc03d44921f493deaae1d33151e3067a6f9f8f",
              "status": "affected",
              "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4",
              "versionType": "git"
            },
            {
              "lessThan": "ab9a70cd2386a0d70c164b0905dd66bc9af52e77",
              "status": "affected",
              "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4",
              "versionType": "git"
            },
            {
              "lessThan": "6df164e29bd4e6505c5a2e0e5f1e1f6957a16a42",
              "status": "affected",
              "version": "0653028e8f1c97fec30710813a001ad8a2ec34f4",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/sunrpc/auth_gss/svcauth_gss.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "lessThan": "6.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.53",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.17.*",
              "status": "unaffected",
              "version": "6.17.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.112",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.53",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17.3",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix null pointer dereference on zero-length checksum\n\nIn xdr_stream_decode_opaque_auth(), zero-length checksum.len causes\nchecksum.data to be set to NULL. This triggers a NPD when accessing\nchecksum.data in gss_krb5_verify_mic_v2(). This patch ensures that\nthe value of checksum.len is not less than XDR_UNIT."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is the server-side RPCSEC_GSS verifier path in the kernel\u0027s SUNRPC server (used by nfsd on TCP/2049), parsing attacker-supplied XDR from a received RPC Call. No local access is needed \u2014 a crafted RPC packet reaches `svcauth_gss_accept()` \u2192 `svcauth_gss_verify_header()` directly.\nAC:L - The attacker deterministically triggers the bug by emitting a single RPC_AUTH_GSS Call with a zero-length verifier body; there is no race, no memory-layout dependency, and no state the attacker cannot influence. Kerberized NFS (CONFIG_SUNRPC_GSS with gssproxy/rpc.svcgssd) is a standard enterprise deployment, not a rare config.\nPR:N - `svcauth_gss_verify_header()` runs before any credential is verified \u2014 it is the code that performs the verification \u2014 and the only gate is an rsc-cache lookup on the GSS context handle, which is a monotonically increasing 64-bit counter starting at 1 (`gss_proxy_save_rsc()`) sent in cleartext on the wire in every RPCSEC_GSS request. An unauthenticated remote attacker can trivially enumerate or sniff a valid handle and then supply the malformed verifier.\nUI:N - The crash is triggered entirely by an inbound RPC message processed by the nfsd service thread. No administrator or client-side action is required.\nS:U - The fault occurs and takes effect within the kernel of the NFS server itself, with no crossing of a virtualization, IOMMU, or other security-authority boundary.\nC:N - The defect is a read of address 0 (`memcpy(\u0026be16_ptr, NULL, 2)`); it faults immediately and returns no data to the attacker. No memory contents are disclosed and no pointer values are leaked over the wire.\nI:N - No attacker-controlled data is written anywhere \u2014 the NULL pointer is only dereferenced for reading, and the request is aborted by the oops. There is no corruption primitive and no authentication bypass (the MIC check itself still fails).\nA:H - The NULL dereference oopses the nfsd kernel thread \u2014 and panics the host outright where `panic_on_oops` is set \u2014 and can be replayed indefinitely to kill every service thread, denying NFS service entirely."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:07:58.258Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/81cec07d303186d0d8c623ef8b5ecd3b81e94cf6"
        },
        {
          "url": "https://git.kernel.org/stable/c/affc03d44921f493deaae1d33151e3067a6f9f8f"
        },
        {
          "url": "https://git.kernel.org/stable/c/ab9a70cd2386a0d70c164b0905dd66bc9af52e77"
        },
        {
          "url": "https://git.kernel.org/stable/c/6df164e29bd4e6505c5a2e0e5f1e1f6957a16a42"
        }
      ],
      "title": "sunrpc: fix null pointer dereference on zero-length checksum",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-40129",
    "datePublished": "2025-11-12T10:23:21.327Z",
    "dateReserved": "2025-04-16T07:20:57.170Z",
    "dateUpdated": "2026-08-05T12:07:58.258Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…