{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-46697", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-09-11T15:12:18.250Z", "datePublished": "2024-09-13T05:29:24.787Z", "dateUpdated": "2026-08-05T11:38:02.067Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:38:02.067Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure that nfsd4_fattr_args.context is zeroed out\n\nIf nfsd4_encode_fattr4 ends up doing a \"goto out\" before we get to\nchecking for the security label, then args.context will be set to\nuninitialized junk on the stack, which we'll then try to free.\nInitialize it early." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL" }, "scenarios": [ { "lang": "en", "value": "AV:N - The vulnerable code is the NFSv4 attribute encoder in the in-kernel NFS server, reached directly from GETATTR/READDIR/OPEN operations in a client-supplied COMPOUND over TCP port 2049. No local access is needed — an attacker acting as an NFS client on the network drives the entire path.\nAC:L - The attacker controls every input needed: the requested attribute bitmap (FATTR4_WORD0_CHANGE/SIZE/ACL/FILEHANDLE) and the condition that forces the early exit, e.g. holding a write delegation and deliberately stalling the CB_GETATTR callback so nfsd4_deleg_getattr_conflict returns nfserr_jukebox, and the operation can be repeated indefinitely. CONFIG_NFSD_V4_SECURITY_LABEL is enabled by all major distributions, so no rare configuration is required.\nPR:N - Reaching nfsd4_encode_fattr4 needs only a filehandle obtained via PUTROOTFH/LOOKUP or PUTFH on an accessible export; with the ubiquitous sec=sys (AUTH_SYS) flavor there is no cryptographic authentication at all — the client simply asserts a uid, so a remote unauthenticated peer permitted by the export list can issue the triggering GETATTR/READDIR.\nUI:N - The attacker issues the NFSv4 COMPOUND requests and holds the conflicting delegation entirely on its own. No action by any administrator or other user on the server is required.\nS:U - The bad free corrupts the kernel's own slab allocator within the same security authority as the nfsd thread. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Freeing an uninitialized pointer — and in the READDIR loop, double-freeing an already-released SELinux context buffer that another allocation now owns — yields a use-after-free giving the attacker a stale reference to live kernel objects, which is the standard primitive for disclosing arbitrary kernel memory. The stack slot is also attacker-groomable via the preceding COMPOUND operations, making the freed target selectable.\nI:H - An arbitrary/double free is a full memory-corruption primitive: the reclaimed slab object can be sprayed with attacker-chosen data from concurrent NFS requests, producing a write primitive and control-flow hijack in kernel context. This is at least as strong as a plain use-after-free, which is scored High.\nA:H - kfree() on arbitrary uninitialized stack residue — a stack pointer, a non-slab address, or an already-freed object — triggers slab corruption, a BUG in the allocator, or an oops in the nfsd kthread, panicking the server. The trigger is repeatable at will, so an attacker can reliably take the NFS server down." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfsd/nfs4xdr.c" ], "versions": [ { "version": "f59388a579c6a395de8f7372b267d3abecd8d6bf", "lessThan": "dd65b324174a64558a16ebbf4c3266e5701185d0", "status": "affected", "versionType": "git" }, { "version": "f59388a579c6a395de8f7372b267d3abecd8d6bf", "lessThan": "f58bab6fd4063913bd8321e99874b8239e9ba726", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/nfsd/nfs4xdr.c" ], "versions": [ { "version": "6.7", "status": "affected" }, { "version": "0", "lessThan": "6.7", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.8", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.10.8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/dd65b324174a64558a16ebbf4c3266e5701185d0" }, { "url": "https://git.kernel.org/stable/c/f58bab6fd4063913bd8321e99874b8239e9ba726" } ], "title": "nfsd: ensure that nfsd4_fattr_args.context is zeroed out", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-09-29T15:05:16.231611Z", "id": "CVE-2024-46697", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-29T15:05:30.417Z" } } ] } }