Loading...
Loading...
The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.
October 30, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-3623
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.