nfsd: don't ignore the return code of svc_proc_register()

Summary

CVECVE-2025-22026
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-04-16 15:15:55 UTC
Updated2026-06-19 13:16:20 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init() ignores the return value of svc_proc_register(). If the procfile creation fails, then the kernel will WARN when it tries to remove the entry later. Fix nfsd_proc_stat_init() to return the same type of pointer as svc_proc_register(), and fix up nfsd_net_init() to check that and fail the nfsd_net construction if it occurs. svc_proc_register() can fail if the dentry can't be allocated, or if an identical dentry already exists. The second case is pretty unlikely in the nfsd_net construction codepath, so if this happens, return -ENOMEM.

Risk And Classification

Primary CVSS: v3.1 5.5 MEDIUM from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: CWE-252

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 5545496966631cd40ad3aa6450be56d0e5773d10 51107e768de6821b68aa34a136d07bc7a09cf6c3 git Not specified
CNA Linux Linux affected 73c43bccf25cec9cdec62fc22a513c28a4b28390 e4316bd85e42b01125b2aab691769234a388b8a3 git Not specified
CNA Linux Linux affected 10ece754df9a799131a1cf3197e9d26c04ddec22 51da899c209a9624e48be416bd30e7ed5cd6c3d8 git Not specified
CNA Linux Linux affected 6f8d6ed3426a17f77628cebfb6a6e2c6f2b2496c 30405b23b4d5e2a596fb756d48119d7293194e75 git Not specified
CNA Linux Linux affected 93483ac5fec62cc1de166051b219d953bb5e4ef4 6a59b70fe71ec66c0dd19e2c279c71846a3fb2f0 git Not specified
CNA Linux Linux affected 93483ac5fec62cc1de166051b219d953bb5e4ef4 e31957a819e60cf0bc9a49408765e6095fd3d046 git Not specified
CNA Linux Linux affected 93483ac5fec62cc1de166051b219d953bb5e4ef4 9d9456185fd5f1891c74354ee297f19538141ead git Not specified
CNA Linux Linux affected 93483ac5fec62cc1de166051b219d953bb5e4ef4 930b64ca0c511521f0abdd1d57ce52b2a6e3476b git Not specified
CNA Linux Linux affected b7b05f98f3f06fea3986b46e5c7fe2928676b02d git Not specified
CNA Linux Linux affected 5.10.226 5.10.259 semver Not specified
CNA Linux Linux affected 5.15.166 5.15.210 semver Not specified
CNA Linux Linux affected 6.1.106 6.1.164 semver Not specified
CNA Linux Linux affected 6.6.47 6.6.125 semver Not specified
CNA Linux Linux affected 6.8.10 6.9 semver Not specified
CNA Linux Linux affected 6.9 Not specified
CNA Linux Linux unaffected 6.9 semver Not specified
CNA Linux Linux unaffected 5.10.259 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.210 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.164 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.125 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.24 6.12.* semver Not specified
CNA Linux Linux unaffected 6.13.12 6.13.* semver Not specified
CNA Linux Linux unaffected 6.14.2 6.14.* semver Not specified
CNA Linux Linux unaffected 6.15 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/9d9456185fd5f1891c74354ee297f19538141ead 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/6a59b70fe71ec66c0dd19e2c279c71846a3fb2f0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/930b64ca0c511521f0abdd1d57ce52b2a6e3476b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/e31957a819e60cf0bc9a49408765e6095fd3d046 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/e4316bd85e42b01125b2aab691769234a388b8a3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/51107e768de6821b68aa34a136d07bc7a09cf6c3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/51da899c209a9624e48be416bd30e7ed5cd6c3d8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/30405b23b4d5e2a596fb756d48119d7293194e75 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report