Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46696

Опубликовано: 13 сент. 2024
Источник: redhat
CVSS3: 7.3

Описание

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

A flaw was found in the nfsd component of the Linux kernel. This use-after-free (UAF) vulnerability occurs because fields embedded in a delegation reference are accessed after the reference has been dropped, making them unsafe. This could lead to a system crash or other unpredictable behavior.

Отчет

This flaw has currently no known exploit.

Меры по смягчению последствий

If NFS server functionality is not required, disable the nfs-server service to prevent the nfsd kernel module from loading and exposing this vulnerability. To disable the service: sudo systemctl disable --now nfs-server This action will stop the NFS server and prevent it from starting automatically on boot. A system reboot may be required to fully unload the nfsd module if it was already in use. Disabling the NFS server will impact any services or clients relying on it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2312084kernel: nfsd: fix potential UAF in nfsd4_cb_getattr_release

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

CVSS3: 9.8
nvd
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

CVSS3: 9.8
debian
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: n ...

CVSS3: 7.8
github
около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость функции nfsd4_cb_getattr_release() сетевой файловой системы Network File System (NFS) ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

7.3 High

CVSS3