Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's NFSv4/pNFS implementation has been addressed. The issue arose because the layout management function 'pnfs_mark_layout_stateid_invalid' did not properly clear the 'NFS_INO_LAYOUTCOMMIT' flag, leading to a potential crash when the layout reference was null. This vulnerability affects the stable versions of the Linux kernel.
The vulnerability could cause a system crash by attempting to reference a null layout, disrupting the NFSv4/pNFS layout management process.
To reproduce this vulnerability, trigger a scenario where the NFSv4/pNFS layout management function 'pnfs_mark_layout_stateid_invalid' is called with a null layout reference. This can occur during normal NFSv4/pNFS operations if the layout management state is not properly maintained, leading to a crash when the system attempts to process the invalid layout reference.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.