CVE-2022-49418
A flaw in the Linux kernel's NFSv4 code can cause a crash when a client follows a referral. The crash can be triggered remotely without authentication, leading to a denial of service. The issue has been fixed in a kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all versions before the patch that includes the NFSv4 referral lookup fix. Typical users are system administrators running servers that use NFSv4.
Real-world impact
An attacker could crash the kernel, causing the system to reboot or become unresponsive, effectively denying service to legitimate users.
Why this severity
The CVSS score of 9.8 indicates that the flaw can be exploited from anywhere, requires no user interaction, and can completely compromise confidentiality, integrity, and availability.
What to do about it
- 011. Identify the current kernel version running on your system.
- 022. Update the kernel to a version that includes the NFSv4 referral lookup fix for CVE-2022-49418.
- 033. Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Feb 26, 2025 · Feb 26, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.