Aller au contenu

Fiche vulnérabilité

CVE-2024-54456 : faille élevée linux linux kernel (CVSS 7.8)

Description

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() name is char[64] where the size of clnt->cl_program->name remains unknown. Invoking strcat() directly will also lead to potential buffer overflow. Change them to strscpy() and strncat() to fix potential issues.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
27 févr. 2025
Dernière mise à jour
4 août 2026

Produits concernés

  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE