CVE-2025-38089
A critical bug in the Linux kernel’s sunrpc service can be triggered by a specially crafted RPC packet, causing the kernel to crash or corrupt memory. The issue occurs when the server misinterprets an authentication error as a garbage argument, leading to a null pointer dereference. The vendor has released a patch that correctly treats the error as an authentication failure.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel 6.4 and 6.16 (and other 6.x versions) on systems that use the sunrpc service, such as NFS servers.
Real-world impact
An attacker could crash the kernel, causing a denial‑of‑service, or corrupt memory, which could lead to privilege escalation or other unintended behavior.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, leading to complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to a version that includes the fix (e.g., 6.4 or later, 6.16 or later).
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Jun 30, 2025 · Jun 30, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/353e75b55e583635bf…patch
- git.kernel.org/stable/c/599c489eea79382123…patch
- git.kernel.org/stable/c/94d10a4dba0bc482f2…patch
- git.kernel.org/stable/c/c90459cd58bb421d27…patch
- github.com/keymaker-arch/NFSundownexploitpatch
- openwall.com/lists/oss-security/2025/07/…mailing list
- openwall.com/lists/oss-security/2025/07/…mailing list