In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm()…
Critical CVSS 9.8
Summary
In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then tr…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/22f45cedf281e6171817c8a3432c44d788c550e1 Patch
- https://git.kernel.org/stable/c/36e83eda90e0e4ac52f259f775b40b2841f8a0a3 Patch
- https://git.kernel.org/stable/c/3f252a73e81aa01660cb426735eab932e6182e8d Patch
- https://git.kernel.org/stable/c/571a5e46c71490285d2d8c06f6b5a7cbf6c7edd1 Patch
- https://git.kernel.org/stable/c/74ad36ed60df561a303a19ecef400c7096b20306 Patch
- https://git.kernel.org/stable/c/908e4ead7f757504d8b345452730636e298cbf68 Patch
- https://git.kernel.org/stable/c/d35ac850410966010e92f401f4e21868a9ea4d8b Patch
- https://git.kernel.org/stable/c/d71abd1ae4e0413707cd42b10c24a11d1aa71772 Patch
- https://git.kernel.org/stable/c/f3aac6cf390d8b80e1d82975faf4ac61175519c0 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html Mailing List
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Timeline
- nvd_ingest NVD