cbcvebase.
CVE-2024-46697
published 2024-09-13

CVE-2024-46697: In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
34.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to checking for the security label, then args.context will be set to uninitialized junk on the stack, which we'll then try to free. Initialize it early.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.9-1 (forky)linux 6.10.9-1 (forky)
linuxlinux
linuxlinux>= f59388a579c6a395de8f7372b267d3abecd8d6bf < dd65b324174a64558a16ebbf4c3266e5701185d0dd65b324174a64558a16ebbf4c3266e5701185d0
linuxlinux>= f59388a579c6a395de8f7372b267d3abecd8d6bf < f58bab6fd4063913bd8321e99874b8239e9ba726f58bab6fd4063913bd8321e99874b8239e9ba726
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.7 < 6.10.86.10.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.