In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then treat it as if there were no confirmed client found at all. In the case where the unconfirmed client is expiring, just fail and return the result from get_client_locked().
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025090401-CVE-2025-38724-5309@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:22387 https://access.redhat.com/errata/RHSA-2025:22387
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:22388 https://access.redhat.com/errata/RHSA-2025:22388
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:22395 https://access.redhat.com/errata/RHSA-2025:22395
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:22392 https://access.redhat.com/errata/RHSA-2025:22392
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:22405 https://access.redhat.com/errata/RHSA-2025:22405
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2025:22571 https://access.redhat.com/errata/RHSA-2025:22571
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:23000 https://access.redhat.com/errata/RHSA-2025:23000
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:23445 https://access.redhat.com/errata/RHSA-2025:23445
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:23463 https://access.redhat.com/errata/RHSA-2025:23463