CVE-2024-41076

MEDIUM

Linux Kernel - Use-After-Free in NFSv4 Security Label Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix memory leak in nfs4_set_security_label We leak nfs_fattr and nfs4_label every time we set a security xattr.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (14)
linux/Kernel 5.16.0 - 6.1.101linux
linux/Kernel 6.2.0 - 6.6.42linux
linux/Kernel 6.7.0 - 6.9.11linux
Linux/Linux < 5.16
Linux/Linux 1b00ad657997c8984a9e627a3bd37ea14f20beb2 - 899604a7c958771840941caff9ee3dd8193d984c
Linux/Linux 1b00ad657997c8984a9e627a3bd37ea14f20beb2 - aad11473f8f4be3df86461081ce35ec5b145ba68
Linux/Linux 1b00ad657997c8984a9e627a3bd37ea14f20beb2 - b98090699319e64f5de1e8db5bb75870f1eb1c6e
Linux/Linux 1b00ad657997c8984a9e627a3bd37ea14f20beb2 - d130220ccc94d74d70da984a199477937e7bf03c
Linux/Linux 5.16
Linux/Linux 6.1.101 - 6.1.*
... and 4 more
Published Jul 29, 2024
Tracked Since Feb 18, 2026