CVE-2024-50241
published 2024-11-09CVE-2024-50241: In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.47%
38.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Initialize struct nfsd4_copy earlier
Ensure the refcount and async_copies fields are initialized early.
cleanup_async_copy() will reference these fields if an error occurs
in nfsd4_copy(). If they are not correctly initialized, at the very
least, a refcount underflow occurs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.11.7-1 (forky) | linux 6.11.7-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 43e46ee5efc03990b223f7aa8b77aa9c3d3acfdf < 7267625baf365a969f1b25ded6f07b64bc90ec5b | 7267625baf365a969f1b25ded6f07b64bc90ec5b |
| linux | linux | >= 6.10.14 < 6.11 | 6.11 |
| linux | linux | >= 6.11.3 < 6.11.7 | 6.11.7 |
| linux | linux | >= 6a488ad7745b8f64625c6d3a24ce7e448e83f11b < e30a9a2f69c34a00a3cb4fd45c5d231929e66fb1 | e30a9a2f69c34a00a3cb4fd45c5d231929e66fb1 |
| linux | linux | >= 7ea9260874b779637aff6d24c344b8ef4ac862a0 < c3074003fa6837c2b89a34d8d12d9463b59d22d6 | c3074003fa6837c2b89a34d8d12d9463b59d22d6 |
| linux | linux | >= 9e52ff544e0bfa09ee339fd7b0937ee3c080c24e < 059434d23c4578d9d02efb92d848ea21bc640112 | 059434d23c4578d9d02efb92d848ea21bc640112 |
| linux | linux | >= aadc3bbea163b6caaaebfdd2b6c4667fbc726752 < 63fab04cbd0f96191b6e5beedc3b643b01c15889 | 63fab04cbd0f96191b6e5beedc3b643b01c15889 |
| linux | linux | >= ae267989b7b7933dfedcd26468d0a88fc3a9da9e < 421f1a2a1afb47d88de09457ef7687e1df7bc997 | 421f1a2a1afb47d88de09457ef7687e1df7bc997 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.11.7-1 | 6.11.7-1 |
| linux | linux_kernel | >= 0 < 6.11.7-1 | 6.11.7-1 |
| linux | linux_kernel | >= 6.10.14 < 6.11.7 | 6.11.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x9gg-ww2m-r7gj: In the Linux kernel, the following vulnerability has been resolved:
NFSD: Initialize struct nfsd4_copy earlier
Ensure the refcount and async_copies
ghsa_unreviewed·2024-11-09
CVE-2024-50241 [MEDIUM] CWE-908 GHSA-x9gg-ww2m-r7gj: In the Linux kernel, the following vulnerability has been resolved:
NFSD: Initialize struct nfsd4_copy earlier
Ensure the refcount and async_copies
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Initialize struct nfsd4_copy earlier
Ensure the refcount and async_copies fields are initialized early.
cleanup_async_copy() will reference these fields if an error occurs
in nfsd4_copy(). If they are not correctly initialized, at the very
least, a refcount underflow occurs.
OSV
CVE-2024-50241: In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fi
osv·2024-11-09·CVSS 5.5
CVE-2024-50241 [MEDIUM] CVE-2024-50241: In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fi
In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are initialized early. cleanup_async_copy() will reference these fields if an error occurs in nfsd4_copy(). If they are not correctly initialized, at the very least, a refcount underflow occurs.
Red Hat
kernel: NFSD: Initialize struct nfsd4_copy earlier
vendor_redhat·2024-11-09·CVSS 5.5
CVE-2024-50241 [MEDIUM] CWE-908 kernel: NFSD: Initialize struct nfsd4_copy earlier
kernel: NFSD: Initialize struct nfsd4_copy earlier
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Initialize struct nfsd4_copy earlier
Ensure the refcount and async_copies fields are initialized early.
cleanup_async_copy() will reference these fields if an error occurs
in nfsd4_copy(). If they are not correctly initialized, at the very
least, a refcount underflow occurs.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
P
Debian
CVE-2024-50241: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: Initi...
vendor_debian·2024·CVSS 5.5
CVE-2024-50241 [MEDIUM] CVE-2024-50241: linux - In the Linux kernel, the following vulnerability has been resolved: NFSD: Initi...
In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are initialized early. cleanup_async_copy() will reference these fields if an error occurs in nfsd4_copy(). If they are not correctly initialized, at the very least, a refcount underflow occurs.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.11.7-1)
sid: resolved (fixed in 6.11.7-1)
trixie: resolved (fixed in 6.11.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/059434d23c4578d9d02efb92d848ea21bc640112https://git.kernel.org/stable/c/421f1a2a1afb47d88de09457ef7687e1df7bc997https://git.kernel.org/stable/c/63fab04cbd0f96191b6e5beedc3b643b01c15889https://git.kernel.org/stable/c/7267625baf365a969f1b25ded6f07b64bc90ec5bhttps://git.kernel.org/stable/c/c3074003fa6837c2b89a34d8d12d9463b59d22d6https://git.kernel.org/stable/c/e30a9a2f69c34a00a3cb4fd45c5d231929e66fb1
2024-11-09
Published