Back

MEDIUM

NFSv4: Fix a credential leak in _nfs4_discover_trunking()

Published Dec 30, 2025

Description

NFSv4: Fix a credential leak in _nfs4_discover_trunking()

Affected products

Remediation

Red Hat statement

A flaw was found in the Linux kernel NFSv4 client where _nfs4_discover_trunking() failed to release a credential reference on an error path, leading to a credential leak. A local attacker can trigger this condition by causing memory allocation failures during NFS trunking discovery, resulting in a kernel resource leak.

Weaknesses (0)

No CWE recorded.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 30, 2025
Updated May 23, 2026
Reserved Dec 30, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 30, 2025
ENISA EUVD
Assigner Linux
Published Dec 30, 2025
Updated May 23, 2026
Exploited since n/a
EUVD-2022-55845