7.8
CVE-2026-31403
- EPSS 0.02%
- Veröffentlicht 03.04.2026 15:16:06
- Zuletzt bearbeitet 27.04.2026 14:16:36
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd
In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd The /proc/fs/nfs/exports proc entry is created at module init and persists for the module's lifetime. exports_proc_open() captures the caller's current network namespace and stores its svc_export_cache in seq->private, but takes no reference on the namespace. If the namespace is subsequently torn down (e.g. container destruction after the opener does setns() to a different namespace), nfsd_net_exit() calls nfsd_export_shutdown() which frees the cache. Subsequent reads on the still-open fd dereference the freed cache_detail, walking a freed hash table. Hold a reference on the struct net for the lifetime of the open file descriptor. This prevents nfsd_net_exit() from running -- and thus prevents nfsd_export_shutdown() from freeing the cache -- while any exports fd is open. cache_detail already stores its net pointer (cd->net, set by cache_create_net()), so exports_release() can retrieve it without additional per-file storage.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
76740c28050dc6db2f5550f1325b00a11bbb3255
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
c7f406fb341d6747634b8b1fa5461656e5e56076
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
d1a19217995df9c7e4118f5a2820c5032fef2945
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
e3d77f935639e6ae4b381c80464c31df998d61f4
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
db4a9f99b12a7ee1c19d86c83a3b752c7effa6c6
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
6a8d70e2ad6aad2c345a5048edcb8168036f97d6
Status
affected
Version
96d851c4d28de8cc83fe2bd5c6bc2eb8f253a6c5
Version <
e7fcf179b82d3a3730fd8615da01b087cc654d0b
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.9
Status
affected
Version
0
Version <
3.9
Status
unaffected
Version <=
5.10.*
Version
5.10.253
Status
unaffected
Version <=
6.1.*
Version
6.1.167
Status
unaffected
Version <=
6.6.*
Version
6.6.130
Status
unaffected
Version <=
6.12.*
Version
6.12.78
Status
unaffected
Version <=
6.18.*
Version
6.18.20
Status
unaffected
Version <=
6.19.*
Version
6.19.10
Status
unaffected
Version <=
*
Version
7.0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.034 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|