CVE-2024-50046
A critical bug in the Linux kernel’s NFSv4 code can cause a crash when certain files are copied on an NFS client. The flaw triggers a NULL‑pointer dereference, potentially allowing an attacker to crash the system. The issue has been fixed in newer kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, particularly versions 6.12 and earlier that run NFSv4 clients.
Real-world impact
An attacker could cause the affected system to crash, resulting in a denial of service and loss of availability.
Why this severity
The CVSS score of 9.8 reflects a critical vulnerability that is network‑exploitable, requires no user interaction or privileges, and can compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the patch for the NFSv4 NULL‑pointer dereference bug.
- 02Reboot the system to load the updated kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Oct 21, 2024 · Oct 21, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/584c019baedddec3fd…patch
- git.kernel.org/stable/c/632344b9efa064ca73…patch
- git.kernel.org/stable/c/a848c29e3486189aaa…patch
- git.kernel.org/stable/c/ef9189bb15dcbe7ed3…patch
- git.kernel.org/stable/c/f892165c564e3aab27…patch
- git.kernel.org/stable/c/fca41e5fa4914d12b2…patch
- lists.debian.org/debian-lts-announce/2025/01…
- lists.debian.org/debian-lts-announce/2025/03…
- cert-portal.siemens.com/productcert/html/ssa-265688…
- cert-portal.siemens.com/productcert/html/ssa-355557…