Answer in brief
CVE-2025-38571 records a Unknown severity vulnerability in sunrpc: fix client side handling of tls alerts. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dea034b963c8901bdcc3d3880c04f0d75c95112f <a55b3d15331859d9fdd261cfa6d34ca2aeb0fb95 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <c36b2fbd60e8f9c6f975522130998608880c93be || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <3ee397eaaca4fa04db21bb98c8f1d0c6cc525368 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <3feada5baf4dc96e151ff2ca54630e1d274e5458 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <cc5d59081fa26506d02de2127ab822f40d88bc5a | a55b3d15331859d9fdd261cfa6d34ca2aeb0fb95, c36b2fbd60e8f9c6f975522130998608880c93be, 3ee397eaaca4fa04db21bb98c8f1d0c6cc525368, 3feada5baf4dc96e151ff2ca54630e1d274e5458, cc5d59081fa26506d02de2127ab822f40d88bc5a |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix client side handling of tls alerts A security exploit was discovered in NFS over TLS in tls_alert_recv due to its assumption that there is valid data in the msghdr's iterator's kvec. Instead, this patch proposes the rework how control messages are setup and used by sock_recvmsg(). If no control message structure is setup, kTLS layer will read and process TLS data record types. As soon as it encounters a TLS control message, it would return an error. At that point, NFS can setup a kvec backed control buffer and read in the control message such as a TLS alert. Scott found that a msg iterator can advance the kvec pointer as a part of the copy process thus we need to revert the iterator before calling into the tls_alert_recv.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-38571 records a Unknown severity vulnerability in sunrpc: fix client side handling of tls alerts. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dea034b963c8901bdcc3d3880c04f0d75c95112f <a55b3d15331859d9fdd261cfa6d34ca2aeb0fb95 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <c36b2fbd60e8f9c6f975522130998608880c93be || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <3ee397eaaca4fa04db21bb98c8f1d0c6cc525368 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <3feada5baf4dc96e151ff2ca54630e1d274e5458 || >=dea034b963c8901bdcc3d3880c04f0d75c95112f <cc5d59081fa26506d02de2127ab822f40d88bc5a | a55b3d15331859d9fdd261cfa6d34ca2aeb0fb95, c36b2fbd60e8f9c6f975522130998608880c93be, 3ee397eaaca4fa04db21bb98c8f1d0c6cc525368, 3feada5baf4dc96e151ff2ca54630e1d274e5458, cc5d59081fa26506d02de2127ab822f40d88bc5a |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix client side handling of tls alerts A security exploit was discovered in NFS over TLS in tls_alert_recv due to its assumption that there is valid data in the msghdr's iterator's kvec. Instead, this patch proposes the rework how control messages are setup and used by sock_recvmsg(). If no control message structure is setup, kTLS layer will read and process TLS data record types. As soon as it encounters a TLS control message, it would return an error. At that point, NFS can setup a kvec backed control buffer and read in the control message such as a TLS alert. Scott found that a msg iterator can advance the kvec pointer as a part of the copy process thus we need to revert the iterator before calling into the tls_alert_recv.
Quoted source text, attributed separately from HOL analysis.