kernel: nfsv4: kernel panic in nfs4_proc_lock()
Published Nov 9, 2009
7.8
HIGHCVSS 2.0
EPSS 12.00%
Description
The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.
Affected products
No data.
- ≤ 2.6.31
- 2.2.27
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.4.8
- 2.4.9
- 2.4.10
- 2.4.11
- 2.4.12
- 2.4.13
- 2.4.14
- 2.4.15
- 2.4.16
- 2.4.17
- 2.4.18
- 2.4.19
- 2.4.20
- 2.4.21
- 2.4.22
- 2.4.23
- 2.4.24
- 2.4.25
- 2.4.26
- 2.4.27
- 2.4.28
- 2.4.29
- 2.4.29
- 2.4.29
- 2.4.30
- 2.4.30
- 2.4.30
- 2.4.31
- 2.4.32
- 2.4.33
- 2.4.34.3
- 2.4.34.4
- 2.4.34.5
- 2.4.34.6
- 2.4.35.1
- 2.4.35.2
- 2.4.35.3
- 2.4.35.4
- 2.4.35.5
- 2.4.36
- 2.4.36.1
- 2.4.36.2
- 2.4.36.3
- 2.4.36.4
- 2.4.36.5
- 2.4.36.6
- 2.4.36.7
- 2.4.36.8
- 2.4.36.9
- 2.4.37
- 2.4.37
- 2.4.37.1
- 2.4.37.2
- 2.4.37.3
- 2.4.37.4
- 2.4.37.5
- 2.4.37.6
- 2.6
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.10
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.16.42
- 2.6.16.43
- 2.6.16.44
- 2.6.16.45
- 2.6.16.46
- 2.6.16.47
- 2.6.16.48
- 2.6.16.49
- 2.6.16.50
- 2.6.16.51
- 2.6.16.52
- 2.6.16.53
- 2.6.16.54
- 2.6.16.55
- 2.6.16.56
- 2.6.16.57
- 2.6.16.58
- 2.6.16.59
- 2.6.16.60
- 2.6.16.61
- 2.6.16.62
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.18.7
- 2.6.18.8
- 2.6.19
- 2.6.19.1
- 2.6.19.2
- 2.6.19.3
- 2.6.19.4
- 2.6.19.5
- 2.6.19.6
- 2.6.19.7
- 2.6.20
- 2.6.20.1
- 2.6.20.2
- 2.6.20.3
- 2.6.20.4
- 2.6.20.5
- 2.6.20.6
- 2.6.20.7
- 2.6.20.8
- 2.6.20.9
- 2.6.20.10
- 2.6.20.11
- 2.6.20.12
- 2.6.20.13
- 2.6.20.14
- 2.6.20.15
- 2.6.20.16
- 2.6.20.17
- 2.6.20.18
- 2.6.20.19
- 2.6.20.20
- 2.6.20.21
- 2.6.21
- 2.6.21.1
- 2.6.21.2
- 2.6.21.3
- 2.6.21.4
- 2.6.21.5
- 2.6.21.6
- 2.6.21.7
- 2.6.22
- 2.6.22.1
- 2.6.22.2
- 2.6.22.3
- 2.6.22.4
- 2.6.22.5
- 2.6.22.6
- 2.6.22.7
- 2.6.22.8
- 2.6.22.9
- 2.6.22.10
- 2.6.22.11
- 2.6.22.12
- 2.6.22.13
- 2.6.22.14
- 2.6.22.15
- 2.6.22.16
- 2.6.22.17
- 2.6.22.18
- 2.6.22.19
- 2.6.22.20
- 2.6.22.21
- 2.6.22.22
- 2.6.22_rc1
- 2.6.22_rc7
- 2.6.23
- 2.6.23
- 2.6.23
- 2.6.23.1
- 2.6.23.2
- 2.6.23.3
- 2.6.23.4
- 2.6.23.5
- 2.6.23.6
- 2.6.23.7
- 2.6.23.8
- 2.6.23.9
- 2.6.23.10
- 2.6.23.11
- 2.6.23.12
- 2.6.23.13
- 2.6.23.14
- 2.6.23.15
- 2.6.23.16
- 2.6.23.17
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24
- 2.6.24.1
- 2.6.24.2
- 2.6.24.3
- 2.6.24.4
- 2.6.24.5
- 2.6.24.6
- 2.6.24.7
- 2.6.25
- 2.6.25
- 2.6.25.1
- 2.6.25.1
- 2.6.25.2
- 2.6.25.2
- 2.6.25.3
- 2.6.25.3
- 2.6.25.4
- 2.6.25.4
- 2.6.25.5
- 2.6.25.5
- 2.6.25.6
- 2.6.25.6
- 2.6.25.7
- 2.6.25.7
- 2.6.25.8
- 2.6.25.8
- 2.6.25.9
- 2.6.25.9
- 2.6.25.10
- 2.6.25.10
- 2.6.25.11
- 2.6.25.11
- 2.6.25.12
- 2.6.25.12
- 2.6.25.13
- 2.6.25.14
- 2.6.25.15
- 2.6.25.16
- 2.6.25.17
- 2.6.25.18
- 2.6.25.19
- 2.6.25.20
- 2.6.26
- 2.6.26
- 2.6.26.1
- 2.6.26.2
- 2.6.26.3
- 2.6.26.4
- 2.6.26.5
- 2.6.26.6
- 2.6.26.7
- 2.6.26.8
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27
- 2.6.27.1
- 2.6.27.2
- 2.6.27.3
- 2.6.27.4
- 2.6.27.5
- 2.6.27.6
- 2.6.27.7
- 2.6.27.8
- 2.6.27.9
- 2.6.27.10
- 2.6.27.11
- 2.6.27.12
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28
- 2.6.28.1
- 2.6.28.2
- 2.6.28.3
- 2.6.28.4
- 2.6.28.5
- 2.6.28.6
- 2.6.28.7
- 2.6.28.8
- 2.6.28.9
- 2.6.29
- 2.6.29
- 2.6.29
- 2.6.29
- 2.6.29
- 2.6.29
- 2.6.29.3
- 2.6.29.5
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.31
- 2.6.31
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-139.el5rt
Fixed · RHSA-2009:1635
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.26.EL
Fixed · RHSA-2010:0474
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.9.1.el5
Fixed · RHSA-2009:1670
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-139.el5rt | Fixed | RHSA-2009:1635 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.26.EL | Fixed | RHSA-2010:0474 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.9.1.el5 | Fixed | RHSA-2009:1670 |
No package ranges for this CVE.
Remediation
Red Hat statement
The Linux kernel as shipped with Red Hat Enterprise Linux 3 did not have support for NFSv4, and therefore is not affected by this issue. It was addressed in Red Hat Enterprise Linux 4, 5, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2010-0474.html, https://rhn.redhat.com/errata/RHSA-2009-1670.html and https://rhn.redhat.com/errata/RHSA-2009-1635.html respectively.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 12.00% (0.12000) | 96.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 12.00% (0.12000) | 95.58th | v5 (v2026.06.15) |
| Mar 30, 2025 | 6.35% (0.06347) | 90.05th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.65% (0.07647) | 86.19th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.46% (0.05462) | 89.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.30% (0.00299) | 70.32th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.30% (0.00299) | 68.66th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.30% (0.00299) | 64.64th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.36% (0.05356) | 89.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.36% (0.05356) | 88.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.36% (0.05356) | 76.09th | v2 (v2022.01.01) |
References (28)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d953126a28f97ec965d23c69fd5795854c048f30 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/37909 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/40218 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2010/dsa-2005 vendor-advisoryx_refsource_DEBIAN
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.31/ChangeLog-2.6.31-rc4 x_refsource_CONFIRMVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:329 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:051 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/11/05/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/11/05/4 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2009-1670.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0474.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/36936 vdb-entryx_refsource_BID
- http://www.spinics.net/linux/lists/linux-nfs/msg03357.html mailing-listx_refsource_MLIST
- http://www.ubuntu.com/usn/usn-864-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-3726 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=529227 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3726
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6636 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9734 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3726
Change history (0)
No recorded changes yet.