Vulnerability identifier: #VU98983
Vulnerability risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-476
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the __cld_pipe_inprogress_downcall() function in fs/nfsd/nfs4recover.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel:
External links
http://git.kernel.org/stable/c/0f1d007bbea38a61cf9c5392708dc70ae9d84a3d
http://git.kernel.org/stable/c/b7b7a8df41ef18862dd6b22289fb46c2c12398af
http://git.kernel.org/stable/c/84a563d136faf514fdad1ade28d7a142fd313cb8
http://git.kernel.org/stable/c/318f70857caab3da9a6ada9bc8c1f4f7591b695e
http://git.kernel.org/stable/c/766d5fbd78f7a52b3888449a0358760477b74602
http://git.kernel.org/stable/c/1ff8be8d008b9ddc8e7043fbddd37d5d451b271b
http://git.kernel.org/stable/c/22451a16b7ab7debefce660672566be887db1637
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.