CVE-2025-40210
Echo vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's NFSv4 COMPOUND implementation was discovered and assigned CVE-2025-40210. The issue was identified when a cap on the number of operations per NFSv4 COMPOUND was removed, leading to potential security risks. The vulnerability was disclosed on November 21, 2025, affecting Linux kernel systems running NFSD (NVD).

Technical details

The vulnerability stems from the removal of operation limits in NFSv4 COMPOUND processing. When an attacker places an arbitrarily large operation count in the COMPOUND header, it triggers a vmalloc error with size 1209533382144, which exceeds total available pages. The error occurs with mode:0xdc0(GFPKERNEL|_GFP_ZERO) settings. Additionally, the pynfs COMP6 testing revealed that the vulnerability leaves connections or leases in an unusual state, causing CLOSE9 operations to hang indefinitely (NVD).

Impact

The vulnerability can lead to memory corruption and potential system resource exhaustion when NFSD attempts to allocate the COMPOUND operation array. This could result in denial of service conditions for affected systems (NVD).

Mitigation and workarounds

The vulnerability has been addressed by restoring the operation-per-COMPOUND limit, but with an increased threshold of 200 operations. This fix helps prevent resource exhaustion while maintaining reasonable functionality (NVD, Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Echo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-62626HIGH7.2
  • EchoEcho
  • libertas-sd8686-firmware
NoYesNov 21, 2025
CVE-2025-9825MEDIUM5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 21, 2025
CVE-2025-40211N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules-internal
NoYesNov 21, 2025
CVE-2025-40210N/AN/A
  • EchoEcho
  • linux
NoYesNov 21, 2025
CVE-2025-9820N/AN/A
  • GnuTLSGnuTLS
  • gnutls-c++-debuginfo
NoYesNov 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management