Critical severity9.8NVD Advisory· Published Sep 13, 2024· Updated Aug 4, 2026
CVE-2024-46696
CVE-2024-46696
Description
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix potential UAF in nfsd4_cb_getattr_release
Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.
Affected products
9cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.9,<6.10.8
- cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.11:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.11:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.11:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.11:rc5:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 6.9
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.