PT-2025-3326 · Linux+8 · Linux Kernel+8

Yang Erkun

·

Published

2025-01-08

·

Updated

2025-10-03

·

CVE-2024-56779

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc6+
Description A memory leak vulnerability has been resolved in the Linux kernel. The issue occurs when concurrent nfsd4 open requests are made, causing the nfsd to lose track of nfs4 openowner, leading to a memory leak. This situation can happen when two rpc task attempt to open the same file simultaneously from the client to the server, and two instances of nfsd run concurrently. Additionally, when echoing 0 to /proc/fs/nfsd/threads, a warning will be triggered.
Recommendations For Linux kernel versions prior to 6.12.0-rc6+, update to a newer version that contains the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable nfsd module to minimize the risk of exploitation. Avoid using the nfsd4 open function in the affected API endpoint until the issue is resolved. Restrict the use of the umount -f command to prevent the memory leak.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17893
ALT-PU-2025-12647
AZL-55349
AZL-55381
BDU:2025-05074
CVE-2024-56779
DLA-4075-1
DLA-4076-1
INFSA-2025_6966
OESA-2025-1093
OESA-2025-1097
OESA-2025-2081
OESA-2025-2082
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:01983-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7387-1
USN-7387-2
USN-7387-3
USN-7388-1
USN-7389-1
USN-7390-1
USN-7391-1
USN-7392-1
USN-7392-2
USN-7392-3
USN-7392-4
USN-7393-1
USN-7401-1
USN-7407-1
USN-7413-1
USN-7421-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7458-1
USN-7459-1
USN-7459-2
USN-7463-1
USN-7468-1
USN-7523-1
USN-7524-1
USN-7539-1
USN-7540-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu