cbcvebase.
CVE-2024-53146
published 2024-12-24

CVE-2024-53146: In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decode_cb_compound4res() does not have to perform arithmetic on the unsafe length value.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 745f7ce5a95e783ba62fe774325829466aec2aa8745f7ce5a95e783ba62fe774325829466aec2aa8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 90adbae9dd158da8331d9fdd32077bd1af04f55390adbae9dd158da8331d9fdd32077bd1af04f553
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3c5f545c9a1f8a1869246f6f3ae8c17289d6a8413c5f545c9a1f8a1869246f6f3ae8c17289d6a841
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 842f1c27a1aef5367e535f9e85c8c3b06352151a842f1c27a1aef5367e535f9e85c8c3b06352151a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < de53c5305184ca1333b87e695d329d1502d694cede53c5305184ca1333b87e695d329d1502d694ce
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dde654cad08fdaac370febb161ec41eb58e9d2a2dde654cad08fdaac370febb161ec41eb58e9d2a2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 084f797dbc7e52209a4ab6dbc7f0109268754eb9084f797dbc7e52209a4ab6dbc7f0109268754eb9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ccd3394f9a7200d6b088553bf38e688620cd27afccd3394f9a7200d6b088553bf38e688620cd27af
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7f33b92e5b18e904a481e6e208486da43e4dc8417f33b92e5b18e904a481e6e208486da43e4dc841
linuxlinux_kernel< 4.19.3254.19.325
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.