CVE-2025-38566
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's kvec.. kTLS implementation splits TLS non-data record payload between the control message buffer (which includes the type such as TLS aler or TLS cipher change) and the rest of the payload (say TLS alert's level/description) which goes into the msg payload buffer. This patch proposes to rework how control messages are setup and used by so...
- CVSS
- 7.5
- EPSS
- 0.59% 44.7% percentile
- CISA KEV
- Not listed
- Published
- 2025.08.20