CVE-2024-42078: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns is created. Currently this can trigger an oops. Move the initialisation earlier before it can possibly be dereferenced.

Affected products

  • Linux Linux Kernel: before 6.8 (fixed in 6.8); from 6.9, before 6.9.8 (fixed in 6.9.8)

Published 2024-07-29. Last modified 2026-06-17.