Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4().
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Linux / Linux6.7 – 6.7
- Linux / Linux0 – 6.7
- Linux / Linux6.8.10 – 6.8.*
- Linux / Linux6.9 – *
- Linux / Linux83ab8678ad0c6f27594c716cafe59c8bbd5e49ef – 6a7b07689af6e4e023404bf69b1230f43b2a15bc
- Linux / Linux83ab8678ad0c6f27594c716cafe59c8bbd5e49ef – 18180a4550d08be4eb0387fe83f02f703f92d4e7
- Linux / Linux kernel6.9 – 6.9
- Linux / Linux kernel6.9 – 6.9
- Linux / Linux kernel6.7 – 6.8.10
- Linux / Linux kernel6.9 – 6.9
- Linux / Linux kernel6.9 – 6.9
- Linux / Linux kernel6.9 – 6.9
- Linux / Linux kernel6.9 – 6.9
- NETAPP / converged_systems_advisor_agent
- NETAPP / h300s_firmware
- NETAPP / h410c_firmware
- NETAPP / h410s_firmware
- NETAPP / h500s_firmware
- NETAPP / h700s_firmware
- NETAPP / hci_compute_node
- NETAPP / solidfire_&_hci_management_node
- NETAPP / solidfire_&_hci_storage_node
Updated 5m ago · 8 sources