Red Hat resolved CVE-2024-54456, a moderate-severity buffer-overflow flaw in the Linux kernel NFS client function nfs_sysfs_link_rpc_client(). The function appended an RPC program name of unknown length to a fixed 64-byte buffer using unsafe strcat() operations, creating a CWE-120 classic buffer-overflow condition. A local low-privileged attacker could potentially disclose information, corrupt memory, execute unauthorized code or commands, or cause a denial of service; Red Hat rates the issue CVSS 7.1, while NVD and CVE.org score it 7.8.
The upstream remediation replaces the unsafe string handling with bounded strscpy() and strncat() calls. Red Hat issued corrected kernels for RHEL 9 and RHEL 10 and later supplied a fix for RHEL 9.6 Extended Update Support; organizations should apply the applicable kernel advisories and reboot into the updated kernel. Red Hat states that the RHEL 9 kernel-rt package will not receive a fix, and RHEL 8 is outside the supported remediation scope.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20095 for Red Hat Enterprise Linux 10 and RHSA-2025:20518 for Red Hat Enterprise Linux 9, addressing CVE-2024-54456 in their kernel packages.
An upstream Linux CVE announcement reported CVE-2024-54456, a potential buffer overflow in the NFS nfs_sysfs_link_rpc_client() function caused by unsafe concatenation into a fixed 64-byte buffer. The upstream remediation replaced the unsafe operations with strscpy() and strncat().
Red Hat released RHSA-2026:2352 to address CVE-2024-54456 for Red Hat Enterprise Linux 9.6 Extended Update Support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.