Back

HIGH

kernel: nfsd4: fix null dereference creating nfsv4 callback client

Published Oct 30, 2009

Description

The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5, or Red Hat Enterprise MRG. Those versions do not include the upstream patch that introduced this vulnerability.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 30, 2009
Updated Aug 7, 2024
Reserved Oct 9, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 15, 2009