CVE-2024-36958

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:converged_systems_advisor_agent:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

History

01 Oct 2025, 14:07

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Netapp h410s
Netapp h300s
Netapp solidfire \& Hci Storage Node
Netapp h410s Firmware
Netapp h700s
Netapp h500s Firmware
Linux linux Kernel
Netapp solidfire \& Hci Management Node
Netapp h500s
Netapp h300s Firmware
Netapp h410c
Netapp
Linux
Netapp hci Compute Node
Netapp h700s Firmware
Netapp converged Systems Advisor Agent
Netapp h410c Firmware
References () https://git.kernel.org/stable/c/18180a4550d08be4eb0387fe83f02f703f92d4e7 - () https://git.kernel.org/stable/c/18180a4550d08be4eb0387fe83f02f703f92d4e7 - Patch
References () https://git.kernel.org/stable/c/6a7b07689af6e4e023404bf69b1230f43b2a15bc - () https://git.kernel.org/stable/c/6a7b07689af6e4e023404bf69b1230f43b2a15bc - Patch
References () https://security.netapp.com/advisory/ntap-20250404-0007/ - () https://security.netapp.com/advisory/ntap-20250404-0007/ - Third Party Advisory
CPE cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:converged_systems_advisor_agent:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

04 Apr 2025, 23:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250404-0007/ -

21 Nov 2024, 09:22

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: NFSD: corrija el error nfsd4_encode_fattr4() Asegúrese de que args.acl se inicialice temprano. Se utiliza en una llamada incondicional a kfree() al salir de nfsd4_encode_fattr4().
References () https://git.kernel.org/stable/c/18180a4550d08be4eb0387fe83f02f703f92d4e7 - () https://git.kernel.org/stable/c/18180a4550d08be4eb0387fe83f02f703f92d4e7 -
References () https://git.kernel.org/stable/c/6a7b07689af6e4e023404bf69b1230f43b2a15bc - () https://git.kernel.org/stable/c/6a7b07689af6e4e023404bf69b1230f43b2a15bc -

30 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 16:15

Updated : 2025-10-01 14:07


NVD link : CVE-2024-36958

Mitre link : CVE-2024-36958

CVE.ORG link : CVE-2024-36958


JSON object : View

Products Affected

netapp

  • h300s
  • h500s_firmware
  • h410s_firmware
  • h300s_firmware
  • solidfire_\&_hci_storage_node
  • h500s
  • h410s
  • converged_systems_advisor_agent
  • h700s_firmware
  • hci_compute_node
  • h700s
  • h410c
  • solidfire_\&_hci_management_node
  • h410c_firmware

linux

  • linux_kernel