In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm()…
严重 CVSS 9.8
摘要
In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then tr…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/22f45cedf281e6171817c8a3432c44d788c550e1 Patch
- https://git.kernel.org/stable/c/36e83eda90e0e4ac52f259f775b40b2841f8a0a3 Patch
- https://git.kernel.org/stable/c/3f252a73e81aa01660cb426735eab932e6182e8d Patch
- https://git.kernel.org/stable/c/571a5e46c71490285d2d8c06f6b5a7cbf6c7edd1 Patch
- https://git.kernel.org/stable/c/74ad36ed60df561a303a19ecef400c7096b20306 Patch
- https://git.kernel.org/stable/c/908e4ead7f757504d8b345452730636e298cbf68 Patch
- https://git.kernel.org/stable/c/d35ac850410966010e92f401f4e21868a9ea4d8b Patch
- https://git.kernel.org/stable/c/d71abd1ae4e0413707cd42b10c24a11d1aa71772 Patch
- https://git.kernel.org/stable/c/f3aac6cf390d8b80e1d82975faf4ac61175519c0 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing List
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
时间线
- nvd_ingest NVD