CVE-2024-42078

MEDIUM

Linux Kernel < 6.8 - Use-After-Free in NFS Server Netns Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns is created. Currently this can trigger an oops. Move the initialisation earlier before it can possibly be dereferenced.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-665
Status published
Products (7)
Linux/Linux < 6.8
Linux/Linux 6.10
Linux/Linux 6.8
Linux/Linux 6.9.8 - 6.9.*
Linux/Linux 7b207ccd983350a5dedd132b57c666186dd02a7c - 7e8b94045bc77ce4f085ddfb9eb04e5760e66169
Linux/Linux 7b207ccd983350a5dedd132b57c666186dd02a7c - e0011bca603c101f2a3c007bdb77f7006fa78fb1
linux/linux_kernel < 6.8
Published Jul 29, 2024
Tracked Since Feb 18, 2026