
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39730 is a vulnerability discovered in the Linux kernel's NFS (Network File System) functionality, specifically in the nfsfhto_dentry() function. The vulnerability was disclosed on September 7, 2025, and affects the Linux kernel's file handling system. The issue stems from insufficient bounds checking of filehandle length before accessing the embedded filehandle (NVD).
The vulnerability exists in the nfsfhto_dentry() function of the Linux kernel's NFS implementation. The core issue involves the function's failure to properly verify the minimal filehandle length before attempting to access the embedded filehandle. This oversight in bounds checking could potentially lead to memory access issues (NVD).
A flaw in the Linux kernel NFS functionality could allow a connected user to send malicious data to the server, potentially leading to out-of-bounds read operations (Red Hat).
The vulnerability has been resolved through a patch that implements proper filehandle bounds checking in the nfsfhto_dentry() function. Multiple kernel versions have received the fix through various commits (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."