CVE-2024-50043

Updated: 2025-08-20 03:09:38.849139

Description:

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible badness in FREE_STATEID When multiple FREE_STATEIDs are sent for the same delegation stateid, it can lead to a possible either use-after-free or counter refcount underflow errors. In nfsd4_free_stateid() under the client lock we find a delegation stateid, however the code drops the lock before calling nfs4_put_stid(), that allows another FREE_STATE to find the stateid again. The first one will proceed to then free the stateid which leads to either use-after-free or decrementing already zeroed counter.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1751916475 2025-07-08 00:19:24
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1753297988 2025-07-24 01:54:07
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1753298320 2025-07-24 01:54:03