{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-46697","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-09-11T15:12:18.250Z","datePublished":"2024-09-13T05:29:24.787Z","dateUpdated":"2026-08-05T11:38:02.067Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:38:02.067Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: ensure that nfsd4_fattr_args.context is zeroed out\n\nIf nfsd4_encode_fattr4 ends up doing a \"goto out\" before we get to\nchecking for the security label, then args.context will be set to\nuninitialized junk on the stack, which we'll then try to free.\nInitialize it early."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is the NFSv4 attribute encoder in the in-kernel NFS server, reached directly from GETATTR/READDIR/OPEN operations in a client-supplied COMPOUND over TCP port 2049. No local access is needed — an attacker acting as an NFS client on the network drives the entire path.\nAC:L - The attacker controls every input needed: the requested attribute bitmap (FATTR4_WORD0_CHANGE/SIZE/ACL/FILEHANDLE) and the condition that forces the early exit, e.g. holding a write delegation and deliberately stalling the CB_GETATTR callback so nfsd4_deleg_getattr_conflict returns nfserr_jukebox, and the operation can be repeated indefinitely. CONFIG_NFSD_V4_SECURITY_LABEL is enabled by all major distributions, so no rare configuration is required.\nPR:N - Reaching nfsd4_encode_fattr4 needs only a filehandle obtained via PUTROOTFH/LOOKUP or PUTFH on an accessible export; with the ubiquitous sec=sys (AUTH_SYS) flavor there is no cryptographic authentication at all — the client simply asserts a uid, so a remote unauthenticated peer permitted by the export list can issue the triggering GETATTR/READDIR.\nUI:N - The attacker issues the NFSv4 COMPOUND requests and holds the conflicting delegation entirely on its own. No action by any administrator or other user on the server is required.\nS:U - The bad free corrupts the kernel's own slab allocator within the same security authority as the nfsd thread. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Freeing an uninitialized pointer — and in the READDIR loop, double-freeing an already-released SELinux context buffer that another allocation now owns — yields a use-after-free giving the attacker a stale reference to live kernel objects, which is the standard primitive for disclosing arbitrary kernel memory. The stack slot is also attacker-groomable via the preceding COMPOUND operations, making the freed target selectable.\nI:H - An arbitrary/double free is a full memory-corruption primitive: the reclaimed slab object can be sprayed with attacker-chosen data from concurrent NFS requests, producing a write primitive and control-flow hijack in kernel context. This is at least as strong as a plain use-after-free, which is scored High.\nA:H - kfree() on arbitrary uninitialized stack residue — a stack pointer, a non-slab address, or an already-freed object — triggers slab corruption, a BUG in the allocator, or an oops in the nfsd kthread, panicking the server. The trigger is repeatable at will, so an attacker can reliably take the NFS server down."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4xdr.c"],"versions":[{"version":"f59388a579c6a395de8f7372b267d3abecd8d6bf","lessThan":"dd65b324174a64558a16ebbf4c3266e5701185d0","status":"affected","versionType":"git"},{"version":"f59388a579c6a395de8f7372b267d3abecd8d6bf","lessThan":"f58bab6fd4063913bd8321e99874b8239e9ba726","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4xdr.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.10.8","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.10.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/dd65b324174a64558a16ebbf4c3266e5701185d0"},{"url":"https://git.kernel.org/stable/c/f58bab6fd4063913bd8321e99874b8239e9ba726"}],"title":"nfsd: ensure that nfsd4_fattr_args.context is zeroed out","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-29T15:05:16.231611Z","id":"CVE-2024-46697","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-29T15:05:30.417Z"}}]}}