VYPR
High severity7.5NVD Advisory· Published Apr 18, 2025· Updated Jul 30, 2026

CVE-2025-39688

CVE-2025-39688

Description

In the Linux kernel, the following vulnerability has been resolved:

nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid()

The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then tries to use the deleg stateid and expects to see NFS4ERR_DELEG_REVOKED, but it gets bad NFS4ERR_BAD_STATEID instead.

When a delegation is revoked, it's initially marked with SC_STATUS_REVOKED, or SC_STATUS_ADMIN_REVOKED and later, it's marked with the SC_STATUS_FREEABLE flag, which denotes that it is waiting for s FREE_STATEID call.

nfs4_lookup_stateid() accepts a statusmask that includes the status flags that a found stateid is allowed to have. Currently, that mask never includes SC_STATUS_FREEABLE, which means that revoked delegations are (almost) never found.

Add SC_STATUS_FREEABLE to the always-allowed status flags, and remove it from nfsd4_delegreturn() since it's now always implied.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Linux/Kernel7 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.11.6,<6.12
    • cpe:2.3:o:linux:linux_kernel:6.12:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.12:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.12:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.12:rc7:*:*:*:*:*:*
    • (no CPE)range: 6.12
    • (no CPE)
  • osv-coords
    Range: >= 6.12.0, < 6.12.23

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.