CVE-2024-49974 addresses a denial-of-service (DoS) vulnerability in the Linux kernel's NFS daemon (NFSD). Unrestricted asynchronous COPY operations could allow clients to initiate numerous long-running copy tasks, consuming system resources and potentially leading to a DoS. The vulnerability has been patched by implementing a per-namespace limit on concurrent background COPY operations. Rated as MEDIUM severity with a CVSS score of 5.5, this vulnerability requires local access and low privileges (AV:L/PR:L) to exploit, with no user interaction needed (UI:N). The primary impact is high availability loss (A:H), as successful exploitation could render the NFS server unresponsive. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.10.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.11, < 6.11.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025kernel: NFSD: Limit the number of concurrent async COPY operations
Oct 21, 2024NFSD: Limit the number of concurrent async COPY operations
Oct 8, 2024