PT-2025-53979 · Linux+2 · Linux Kernel+2
Publicado
2022-11-28
·
Atualizado
2026-02-24
·
CVE-2022-50861
CVSS v2.0
5.5
Média
| Vetor | AV:L/AC:H/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Linux kernel's Network File System Daemon (NFSD) related to the NFSv2 GETACL result encoder. A conversion oversight within the xdr stream encoders resulted in the inclusion of extraneous data beyond the intended message boundary. While clients generally disregard this extra data, the NFSD process unnecessarily transmits it, leading to a memory leak of stale content. The issue stems from improperly setting the page length of the send buffer during the XDR stream conversion process.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat