Bug 2422768 (CVE-2025-68243) - CVE-2025-68243 kernel: NFS: Check the TLS certificate fields in nfs_match_client()
Summary: CVE-2025-68243 kernel: NFS: Check the TLS certificate fields in nfs_match_cli...
Keywords:
Status: NEW
Alias: CVE-2025-68243
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-16 15:03 UTC by OSIDB Bzimport
Modified: 2025-12-19 04:51 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-12-16 15:03:33 UTC
In the Linux kernel, the following vulnerability has been resolved:

NFS: Check the TLS certificate fields in nfs_match_client()

If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the
cert_serial and privkey_serial fields need to match as well since they
define the client's identity, as presented to the server.


Note You need to log in before you can comment on or make changes to this bug.