Database/Control plane, storage & DevOps
Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4
CVSS 9.1CVE-2024-53146Control plane, storage & DevOpscurated
Impact
An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4 arithmetic, producing a wrong allocation and out-of-bounds access on the server. A single crafted COMPOUND from an unauthenticated client crashes the shared file server.
Who can reach it
Any host that can send an NFSv4 COMPOUND to the server's RPC port.
What to do
Update the storage server kernel and reboot. No config workaround - COMPOUND is the base NFSv4 transport unit.
References
Related entries
- GitHub Enterprise Server: Improper signature verificationCVE-2024-9487 · GitHub Enterprise ServerCritical
- Palo Alto PAN-OS: Management web interface auth bypass invoking PHP scriptsCVE-2025-0108 · Palo Alto PAN-OSCritical
- Arm Neoverse N1 / N2 / V1 / V2 / V3 / V3AE, Cortex-A76/A77/A78/A710, Cortex-X1-X925, C1-Ultra/PremiumCVE-2025-10263 · Arm Neoverse N1 / N2 / V1 / V2 / V3 / V3AE, Cortex-A76/A77/A78/A710, Cortex-X1-X925, C1-Ultra/Premium; Trusted…Critical
- Dell CloudLink (restricted shell breakout): A privileged user breaks out of the restricted shell into a full commandCVE-2025-45378 · Dell CloudLink (restricted shell breakout)Critical
- Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLinkCVE-2025-46364 · Dell CloudLink (CLI escape)Critical
- OAuth2-Proxy: skip_auth_routes route matching flawCVE-2025-54576 · OAuth2-ProxyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.