Linux Kernel NFSV4 CallbackClient NULL Pointer Dereference Local Denial of Service

03 November 2009
Bookmark and Share
The Linux kernel is exposed to a local denial of service issue. It is exposed to this issue because when the "rpcauth_lookup_credcache()" function is called, it assumes that the given authentication flavor has a credential cache. When attempting to mount an nfsv4 filesystem and using the "auth_null" authentication flavor, a NULL-pointer dereference can occur. Linux Kernel version Linux kernel 2.6.31 -rc1 is affected by this issue.

Ref: http://www.securityfocus.com/bid/36794

09.44.17 - CVE: Not Available
Platform: Linux