CVE-2024-54456: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() name is char[64] where the size of clnt->cl_program->name remains unknown. Invoking strcat() directly will also lead to potential buffer overflow. Change them to strscpy() and strncat() to fix potential issues.
Affected products
- Linux Linux Kernel: from 6.5, before 6.6.79 (fixed in 6.6.79); from 6.7, before 6.12.16 (fixed in 6.12.16); from 6.13, before 6.13.4 (fixed in 6.13.4)
Published 2025-02-27. Last modified 2026-08-04.