Executive brief
A security vulnerability has been identified in the Linux Kernel's Network File System (NFS) component, which is used for sharing files across a network. A local attacker with system access could exploit this flaw to cause a complete system crash or potentially access sensitive information stored in the system's memory. This could lead to service disruptions or the exposure of confidential data.
Technical details
A use-after-free (UAF) vulnerability exists in the nfsd4_ssc_setup_dul function within fs/nfsd/nfs4proc.c of the Linux Kernel's NFS server implementation. The flaw occurs during the setup of server-side copy (SSC) operations. A local attacker with low privileges can trigger this condition to cause a kernel panic (denial of service) or read sensitive kernel memory (information disclosure). The issue affects various kernel versions including branches 5.14.x, 5.16.x, and 6.1.x, and was addressed in version 6.2. Patches are available through major Linux distributions and upstream kernel updates.
Affected products
- Linux Linux Kernel versions up to (excluding) 6.2; 5.14 to 5.15.91; 5.16 to 6.1.9
- Red Hat Enterprise Linux 9.0
- Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem All versions
Timeline
- 2023-03-29: disclosed: Initial NVD publication
- 2023-03-29: advisory: Red Hat advisory published
- 2024-04-09: advisory: Siemens advisory published for SIMATIC S7-1500