cbcvebase.
CVE-2024-50241
published 2024-11-09

CVE-2024-50241: In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.47%
38.5th percentile
In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are initialized early. cleanup_async_copy() will reference these fields if an error occurs in nfsd4_copy(). If they are not correctly initialized, at the very least, a refcount underflow occurs.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.7-1 (forky)linux 6.11.7-1 (forky)
linuxlinux
linuxlinux>= 43e46ee5efc03990b223f7aa8b77aa9c3d3acfdf < 7267625baf365a969f1b25ded6f07b64bc90ec5b7267625baf365a969f1b25ded6f07b64bc90ec5b
linuxlinux>= 6.10.14 < 6.116.11
linuxlinux>= 6.11.3 < 6.11.76.11.7
linuxlinux>= 6a488ad7745b8f64625c6d3a24ce7e448e83f11b < e30a9a2f69c34a00a3cb4fd45c5d231929e66fb1e30a9a2f69c34a00a3cb4fd45c5d231929e66fb1
linuxlinux>= 7ea9260874b779637aff6d24c344b8ef4ac862a0 < c3074003fa6837c2b89a34d8d12d9463b59d22d6c3074003fa6837c2b89a34d8d12d9463b59d22d6
linuxlinux>= 9e52ff544e0bfa09ee339fd7b0937ee3c080c24e < 059434d23c4578d9d02efb92d848ea21bc640112059434d23c4578d9d02efb92d848ea21bc640112
linuxlinux>= aadc3bbea163b6caaaebfdd2b6c4667fbc726752 < 63fab04cbd0f96191b6e5beedc3b643b01c1588963fab04cbd0f96191b6e5beedc3b643b01c15889
linuxlinux>= ae267989b7b7933dfedcd26468d0a88fc3a9da9e < 421f1a2a1afb47d88de09457ef7687e1df7bc997421f1a2a1afb47d88de09457ef7687e1df7bc997
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 6.10.14 < 6.11.76.11.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.