CVE-2024-46697
A critical flaw in the Linux kernel’s NFS server could let attackers read or modify data. The bug occurs when the kernel fails to clear a memory field, potentially exposing sensitive information. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel 6.11 and earlier versions running the NFS server. Typical users are system administrators and organizations that expose NFS shares.
Real-world impact
An attacker could read or modify data on the NFS server, potentially compromising confidentiality, integrity, and availability of files shared over NFS.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely with no authentication, and it can lead to full compromise of the affected system, affecting confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your system to the latest Linux kernel release that includes the patch.
- 02Reboot into the new kernel to apply the fix.
NVD-referenced vendor advisory
Timeline
- Sep 13, 2024 · Sep 13, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.