PT-2025-37682 · Unknown+8 · Nfsd4 Encode Operation+9
CVE-2023-53241
·
Publicado
2023-11-07
·
Atualizado
2026-04-14
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue where the
op release function is not consistently called, even when op func returns an error. This can lead to a memory leak in the layoutget codepath, specifically within the Network File System (NFS) daemon (nfsd) when handling operations with "trivial" replies. The nfsd4 encode operation function skips calling op release under certain conditions, causing the memory leak. Additionally, nfsd4 block get device info scsi needs to set the gd device pointer to NULL on error to prevent a double free.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Leak
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Centos
Linux Kernel
Nfs
Red Hat
Red Os
Suse
Nfsd
Nfsd4 Block Get Device Info Scsi
Nfsd4 Encode Operation