PT-2025-3652 · Linux+1 · Linux Kernel+1

Max Kellermann

·

Published

2024-12-13

·

Updated

2025-09-29

·

CVE-2024-57927

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when netfslib attempts to copy data on behalf of nfs, creating a new write request and calling nfs netfs init request() with a NULL file pointer, causing nfs file open context() to fail. The fix involves returning if no file pointer is given and emitting a warning for non-copy-to-cache requests. Additionally, nfs netfs free request() is modified to not free the context if the pointer is NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2025-3467
BDU:2025-15886
CVE-2024-57927

Affected Products

Alt Linux
Linux Kernel