CVE-2022-24448 affects Linux kernel NFS directory-open handling: an application opening a path on a mounted NFS filesystem with O_DIRECTORY could receive an uninitialized file descriptor if the NFS server returned a regular file during lookup, rather than the expected ENOTDIR error. The resulting condition can disclose uninitialized kernel data to local, low-privileged users.
The upstream NFSv4 fix validates lookup results when LOOKUP_DIRECTORY is set and returns ENOTDIR for non-directory objects. Red Hat rated the issue CVSS 3.3 (Low) and released corrected kernel packages for affected RHEL 8, RHEL 8.6 EUS, RHEL 9, and Red Hat Virtualization 4 on RHEL 8; its RHEL 6 and RHEL 7 kernel variants are marked will not fix.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:7444 for RHEL 8 kernel-rt and RHSA-2022:7683 for the RHEL 8 kernel to fix CVE-2022-24448, an NFS flaw that could disclose uninitialized kernel data to userspace.
RHSA-2024:0724 fixed CVE-2022-24448 in the RHEL 8.6 Extended Update Support kernel and the Red Hat Virtualization 4 kernel for RHEL 8.
Red Hat issued RHSA-2022:8267 for the RHEL 9 kernel and RHSA-2022:7933 for RHEL 9 kernel-rt to address CVE-2022-24448.
Linux kernel commit ac795161c93699d600db16c1a8cc23a65a1eceaf was committed to validate directory lookup results in the NFS atomic-open path and return ENOTDIR for regular files, preventing return of a file descriptor with uninitialized open state.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.