CVE-2024-58092 – Linux Kernel NFSd Double Initialization Double-Free Vulnerability

The following table lists the changes that have been made to the
CVE-2024-58092 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Apr. 16, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    nfsd: fix legacy client tracking initialization

    Get rid of the nfsd4_legacy_tracking_ops->init() call in
    check_for_legacy_methods(). That will be handled in the caller
    (nfsd4_client_tracking_init()). Otherwise, we’ll wind up calling
    nfsd4_legacy_tracking_ops->init() twice, and the second time we’ll
    trigger the BUG_ON() in nfsd4_init_recdir().

    Added Reference https://git.kernel.org/stable/c/95407304253a4bf03494d921c6913e220c26cc63
    Added Reference https://git.kernel.org/stable/c/cdd66082b227eb695cbf54b7c121ea032e869981
    Added Reference https://git.kernel.org/stable/c/de71d4e211eddb670b285a0ea477a299601ce1ca
Share the Post:

Related Posts