{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-53073","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-11-19T17:17:24.976Z","datePublished":"2024-11-19T17:31:38.040Z","dateUpdated":"2026-08-05T11:43:27.288Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:43:27.288Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Never decrement pending_async_copies on error\n\nThe error flow in nfsd4_copy() calls cleanup_async_copy(), which\nalready decrements nn->pending_async_copies."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in nfsd's NFSv4.2 COPY handler (`nfsd4_copy()`), reached purely by sending a COMPOUND containing OP_COPY to the in-kernel NFS server over TCP/2049. No local access to the server is needed.\nAC:L - The attacker fully controls both preconditions — create a large file, issue more than `sp_nrthreads` concurrent async COPY requests to exceed the cap, then every subsequent COPY deterministically hits the buggy error path. There is no race or uncontrolled state involved.\nPR:N - Triggering requires only an NFSv4.2 session and open stateids, which any host permitted by the export obtains without credential verification under the default AUTH_SYS — the same treatment given to other network-reachable nfsd CVEs (CVE-2024-53217, CVE-2024-56779).\nUI:N - The attacker's own NFS client issues the COPY requests; no action by an administrator or local user on the server is required beyond nfsd already serving an export.\nS:U - The imbalance corrupts only nfsd's own per-netns accounting and exhausts kernel resources within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - The defect is a counter/refcount accounting error with no out-of-bounds or freed-memory access — refcount saturation prevents the premature free, so no kernel memory contents are disclosed to the attacker.\nI:N - No memory corruption occurs: the object is either freed exactly once or leaked, giving no write primitive and no way to modify file data or kernel state beyond the counter itself.\nA:H - Each rejected request either leaks a `struct nfsd4_copy` with a `refcount_t` underflow WARN (kernel panic under `panic_on_warn`) or drives `pending_async_copies` negative until the cap stops working, permitting unbounded concurrent \"copy thread\" kthreads and unbounded long-running server-side copies — remote kernel memory/thread exhaustion and NFS server DoS."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"9e52ff544e0bfa09ee339fd7b0937ee3c080c24e","lessThan":"ed98d26021db0fe62c327aa9f5e57a90bff3fa94","status":"affected","versionType":"git"},{"version":"43e46ee5efc03990b223f7aa8b77aa9c3d3acfdf","lessThan":"9467c49437e948c541569007cd412d577942e635","status":"affected","versionType":"git"},{"version":"7ea9260874b779637aff6d24c344b8ef4ac862a0","lessThan":"949ee5d44d1fd95119b29b3382a933cdc617bf9e","status":"affected","versionType":"git"},{"version":"ae267989b7b7933dfedcd26468d0a88fc3a9da9e","lessThan":"fb79d68a36e21960341ccab07d1ac06d93830321","status":"affected","versionType":"git"},{"version":"6a488ad7745b8f64625c6d3a24ce7e448e83f11b","lessThan":"1421883aa30c5d26bc3370e2d19cb350f0d5ca28","status":"affected","versionType":"git"},{"version":"aadc3bbea163b6caaaebfdd2b6c4667fbc726752","lessThan":"8286f8b622990194207df9ab852e0f87c60d35e9","status":"affected","versionType":"git"},{"version":"b4e21431a0db4854b5023cd5af001be557e6c3db","status":"affected","versionType":"git"},{"version":"6.10.14","lessThan":"6.11","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4proc.c"],"versions":[{"version":"6.11.3","lessThan":"6.11.7","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11.3","versionEndExcluding":"6.11.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10.14"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ed98d26021db0fe62c327aa9f5e57a90bff3fa94"},{"url":"https://git.kernel.org/stable/c/9467c49437e948c541569007cd412d577942e635"},{"url":"https://git.kernel.org/stable/c/949ee5d44d1fd95119b29b3382a933cdc617bf9e"},{"url":"https://git.kernel.org/stable/c/fb79d68a36e21960341ccab07d1ac06d93830321"},{"url":"https://git.kernel.org/stable/c/1421883aa30c5d26bc3370e2d19cb350f0d5ca28"},{"url":"https://git.kernel.org/stable/c/8286f8b622990194207df9ab852e0f87c60d35e9"}],"title":"NFSD: Never decrement pending_async_copies on error","x_generator":{"engine":"bippy-1.2.0"}}}}