In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit(). nfsd_nl_listener_set_doit() uses get_current_cred() without put_cred(). As we can see from other callers, svc_xprt_create_from_sa() does not require the extra refcount. nfsd_nl_listener_set_doit() is always in the process context, sendmsg(), and current->cred does not go away. Let's use current_cred() in nfsd_nl_listener_set_doit().
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | V100R001C10SPC700B010 |
| Linux | Linux | V500R002C00SPC700 |
| Linux | Linux | 2008 R2 for x64-based Systems Service Pack 1 |
| Linux | Linux | 2012 |