🛡️ AZL-53909 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-53066 affecting package kernel for versions less than 6.6.64.2-1

In the Linux kernel, the following vulnerability has been resolved:

nfs: Fix KMSAN warning in decode_getfattr_attrs()

Fix the following KMSAN warning:

CPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B

Tainted: [B]=BAD_PAGE

Hardware name: QEMU Standard PC (Q35 + ICH9, 2009)

=====================================================

=====================================================

BUG: KMSAN: uninit-value in decode_getfattr_attrs+0x2d6d/0x2f90

decode_getfattr_attrs+0x2d6d/0x2f90

decode_getfattr_generic+0x806/0xb00

nfs4_xdr_dec_getattr+0x1de/0x240

rpcauth_unwrap_resp_decode+0xab/0x100

rpcauth_unwrap_resp+0x95/0xc0

call_decode+0x4ff/0xb50

__rpc_execute+0x57b/0x19d0

rpc_execute+0x368/0x5e0

rpc_run_task+0xcfe/0xee0

nfs4_proc_getattr+0x5b5/0x990

__nfs_revalidate_inode+0x477/0xd00

nfs_access_get_cached+0x1021/0x1cc0

nfs_do_access+0x9f/0xae0

nfs_permission+0x1e4/0x8c0

inode_permission+0x356/0x6c0

link_path_walk+0x958/0x1330

path_lookupat+0xce/0x6b0

filename_lookup+0x23e/0x770

vfs_statx+0xe7/0x970

vfs_fstatat+0x1f2/0x2c0

__se_sys_newfstatat+0x67/0x880

__x64_sys_newfstatat+0xbd/0x120

x64_sys_call+0x1826/0x3cf0

do_syscall_64+0xd0/0x1b0

entry_SYSCALL_64_after_hwframe+0x77/0x7f

The KMSAN warning is triggered in decode_getfattr_attrs(), when calling

decode_attr_mdsthreshold(). It appears that fattr->mdsthreshold is not

initialized.

Fix the issue by initializing fattr->mdsthreshold to NULL in

nfs_fattr_init().

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

AZL-53909 is recorded against 1 package.

  • kernel (fixed in 6.6.64.2-1)

Timeline and source

Published on 19 November 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-19
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.6.64.2-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-53909?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-53909 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.