Database/Control plane, storage & DevOps
Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page array
CVSS 7.5CVE-2022-43945Control plane, storage & DevOpscurated
Impact
NFSD buffer overflow - a client can force the send buffer to overflow the page array
Who can reach it
Network (remote)
What to do
Data-plane: kernel patch + rolling reboot of every NFS server - tenant-visible
References
Related entries
- Linux nfsd (NFS server): Broken RELEASE_LOCKOWNER handling in nfsd causing state corruptionCVE-2024-26629 · Linux nfsd (NFS server)Medium
- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickCVE-2022-48340 · GlusterFS (dht translator, dht_setxattr_mds_cbk)High
- AMD SMM communications buffer - TOCTOU (AMD-SB-3003): A time-of-check-to-time-of-use race on the SMM communicationsCVE-2023-20578 · AMD SMM communications buffer - TOCTOU (AMD-SB-3003)High
- NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management andCVE-2023-27314 · NetApp ONTAP 9 HTTP serviceHigh
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedCVE-2023-27532 · Veeam Backup & ReplicationHigh
- MinIO: Cluster returns all env vars incl. MINIO_SECRET_KEY and MINIO_ROOT_PASSWORDCVE-2023-28432 · MinIOHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.