CVE-2024-53146

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53146
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53146.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53146
Downstream
Related
Published
2024-12-24T11:28:46.883Z
Modified
2025-11-28T02:34:04.113861Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
NFSD: Prevent a potential integer overflow
Details

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent a potential integer overflow

If the tag length is >= U32MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decodecb_compound4res() does not have to perform arithmetic on the unsafe length value.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53146.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
745f7ce5a95e783ba62fe774325829466aec2aa8
Fixed
90adbae9dd158da8331d9fdd32077bd1af04f553
Fixed
3c5f545c9a1f8a1869246f6f3ae8c17289d6a841
Fixed
842f1c27a1aef5367e535f9e85c8c3b06352151a
Fixed
de53c5305184ca1333b87e695d329d1502d694ce
Fixed
dde654cad08fdaac370febb161ec41eb58e9d2a2
Fixed
084f797dbc7e52209a4ab6dbc7f0109268754eb9
Fixed
ccd3394f9a7200d6b088553bf38e688620cd27af
Fixed
7f33b92e5b18e904a481e6e208486da43e4dc841

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.325
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.287
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.231
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.174
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.64
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.11
Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.2