In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calling it with an out-of-bounds opnum value. nfsd4_decode_compound() is not so careful, and can invoke OPDESC() with opnum set to OP_ILLEGAL, which is 10044 -- well beyond the end of nfsd4_ops[].
Update Linux/Linux to 50827896c365e0f6c8b55ed56d444dafd87c92c5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanNFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calling it with an out-of-bounds opnum value. nfsd4_decode_compound() is not so careful, and can invoke OPDESC() with opnum set to OP_ILLEGAL, which is 10044 -- well beyond the end of nfsd4_ops[].
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <50827896c365e0f6c8b55ed56d444dafd87c92c5 || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <a64160124d5a078be0c380b1e8a0bad2d040d3a1 || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <ffcbcf087581ae68ddc0a21460f7ecd4315bdd0e || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <f352c41fa718482979e7e6b71b4da2b718e381cc || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <804d8e0a6e54427268790472781e03bc243f4ee3 |
In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calling it with an out-of-bounds opnum value. nfsd4_decode_compound() is not so careful, and can invoke OPDESC() with opnum set to OP_ILLEGAL, which is 10044 -- well beyond the end of nfsd4_ops[].
Update Linux/Linux to 50827896c365e0f6c8b55ed56d444dafd87c92c5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanNFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calling it with an out-of-bounds opnum value. nfsd4_decode_compound() is not so careful, and can invoke OPDESC() with opnum set to OP_ILLEGAL, which is 10044 -- well beyond the end of nfsd4_ops[].
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <50827896c365e0f6c8b55ed56d444dafd87c92c5 || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <a64160124d5a078be0c380b1e8a0bad2d040d3a1 || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <ffcbcf087581ae68ddc0a21460f7ecd4315bdd0e || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <f352c41fa718482979e7e6b71b4da2b718e381cc || >=f4f9ef4a1b0a1ca80b152e28e176d69515bdf7e8 <804d8e0a6e54427268790472781e03bc243f4ee3 |
| 50827896c365e0f6c8b55ed56d444dafd87c92c5, a64160124d5a078be0c380b1e8a0bad2d040d3a1, ffcbcf087581ae68ddc0a21460f7ecd4315bdd0e, f352c41fa718482979e7e6b71b4da2b718e381cc, 804d8e0a6e54427268790472781e03bc243f4ee3 |
| Linux/Linuxgeneric | 4.14 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 50827896c365e0f6c8b55ed56d444dafd87c92c5, a64160124d5a078be0c380b1e8a0bad2d040d3a1, ffcbcf087581ae68ddc0a21460f7ecd4315bdd0e, f352c41fa718482979e7e6b71b4da2b718e381cc, 804d8e0a6e54427268790472781e03bc243f4ee3 |
| Linux/Linuxgeneric | 4.14 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard