🛡️ CVE-2025-40326 — kernel

🟠 CVSS 7.5 — High ✅ No Known Exploit NVD
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

NFSD: Define actions for the new time_deleg FATTR4 attributes

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Define actions for the new time_deleg FATTR4 attributes

NFSv4 clients won't send legitimate GETATTR requests for these new

attributes because they are intended to be used only with CB_GETATTR

and SETATTR. But NFSD has to do something besides crashing if it

ever sees a GETATTR request that queries these attributes.

RFC 8881 Section 18.7.3 states:

> The server MUST return a value for each attribute that the client

> requests if the attribute is supported by the server for the

> target file system. If the server does not support a particular

> attribute on the target file system, then it MUST NOT return the

> attribute value and MUST NOT set the attribute bit in the result

> bitmap. The server MUST return an error if it supports an

> attribute on the target but cannot obtain its value. In that case,

> no attribute values will be returned.

Further, RFC 9754 Section 5 states:

> These new attributes are invalid to be used with GETATTR, VERIFY,

> and NVERIFY, and they can only be used with CB_GETATTR and SETATTR

> by a client holding an appropriate delegation.

Thus there does not appear to be a specific server response mandated

by specification. Taking the guidance that querying these attributes

via GETATTR is "invalid", NFSD will return nfserr_inval, failing the

request entirely.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2025-40326 is recorded against 2 packages.

  • kernel (from 6.14.0 up to 6.17.8)
  • unknown

Timeline and source

Published on 8 December 2025 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2025-40326 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity High
CVSS Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-08
Updated 2026-08-12
Modified 2026-08-06
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.14.0 6.17.8
unknown

Similar Threats

Site Security Check

Is kernel part of your stack?

CVE-2025-40326 is rated CVSS 7.5 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.