CVE-2024-36958
A vulnerability in the Linux kernel's Network File System (NFSD) component can cause the system to crash. This issue occurs because a specific function fails to properly initialize a variable before attempting to free its memory.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel, specifically including version 6.9, and certain NetApp systems such as SolidFire and HCI components.
Real-world impact
An attacker could potentially cause a system crash, leading to a denial of service where the affected machine becomes unresponsive.
Why this severity
This is rated as critical because the vulnerability can be exploited remotely over a network without requiring any user interaction or special privileges, potentially leading to a complete system crash.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for nfsd4_encode_fattr4().
NVD-referenced vendor advisory
Timeline
- May 30, 2024 · May 30, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.