CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel, specifically in the NLM (Network Lock Manager) functionality, where a NULL dereference occurs during lockowner allocation failure. This can lead to a system crash due to improper handling of file lock operations when memory allocation fails. Administrators managing Linux systems should prioritize this issue to prevent potential service disruptions and ensure system stability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private(). That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed. Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully.