VDB

RHBA-2024%3A7236

RHBA-2024%3A7236 PUBLISHED CVSS 7 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call, then we must not try to free either the open slot or the layoutget operation arguments, since they are likely still in use by the hung RPC call.

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhel8/flatpak-sdk@sha256:901255695a80a8311a7b0d741e94a0b59ee72a0fd89713a4fc291d36450fe9b5_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 8)rhel8/flatpak-sdk@sha256:901255695a80a8311a7b0d741e94a0b59ee72a0fd89713a4fc291d36450fe9b5_amd64

Timeline

  • Sep 26, 2024 CVE Published
  • Nov 21, 2025 CVE Updated
  • May 2, 2026 Distribution Patch
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›