CVE-2024-53146

Updated: 2025-01-14 18:08:58.36308

Description:

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decode_cb_compound4res() does not have to perform arithmetic on the unsafe length value.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-01-16 04:34:58
AlmaLinux 9.2 FIPS kernel 5.14.0 5.5 MEDIUM Ignored 2025-01-16 04:34:59
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-01-16 01:41:27
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-01-16 04:34:56
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-01-16 04:34:57
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-01-16 04:34:58
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-01-16 04:34:56
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-01-16 01:41:27
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-01-16 04:34:55
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-01-16 04:34:56
Total: 14