9.8

CVE-2026-72317

SUNRPC: pin upper rpc_clnt across the TLS connect_worker

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: pin upper rpc_clnt across the TLS connect_worker

The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw pointer
and queues the worker; for TLS-secured transports that worker
is xs_tcp_tls_setup_socket(), which reads several fields out
of the saved pointer (cl_timeout, cl_program, cl_prog,
cl_vers, cl_cred, cl_stats) to construct the args for the
inner handshake rpc_clnt.

The xprt does not reference the rpc_clnt; the rpc_clnt
references the xprt. xs_destroy() does cancel the
connect_worker, but it runs only when the xprt's refcount
drops to zero, which cannot happen until the rpc_clnt
releases its cl_xprt reference in rpc_free_client_work().
When a TLS handshake fails fatally (for example, an mTLS
mount whose client cert does not match the server), the
connecting task is woken with -EACCES and exits, the mount
caller invokes rpc_shutdown_client(), and the upper rpc_clnt
is freed before the queued connect_worker fires.
xs_tcp_tls_setup_socket() then dereferences the freed clnt,
producing the refcount_t underflow Michael Nemanov reported.

Take a reference on the upper rpc_clnt in xs_connect() for
TLS transports via a new rpc_hold_client() helper, and drop
it in the connect_worker's exit path with rpc_release_client().
The xprt_lock_connect() / xprt_unlock_connect() pairing
already serialises xs_connect() with xs_tcp_tls_setup_socket(),
so the take and release are balanced one-for-one.

The non-TLS connect worker (xs_tcp_setup_socket) never reads
sock_xprt::clnt, so leave that path alone and avoid the
clnt-holds-xprt-holds-clnt cycle that would otherwise prevent
xprt destruction.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 75eb6af7acdf566c68d61e98e67ee2f235201c02
Version < 79cd550f8c884523b604fbfa43eb02def74d6224
Status affected
Version 75eb6af7acdf566c68d61e98e67ee2f235201c02
Version < 7a65b41b657b71d5a77861f47dd13eb4bc8e10d0
Status affected
Version 75eb6af7acdf566c68d61e98e67ee2f235201c02
Version < 5b0427ba582d143a364301f825f4e32272f06d2d
Status affected
Version 75eb6af7acdf566c68d61e98e67ee2f235201c02
Version < d49f6d098ed48775b9d27a9f9c5c220fdf76f102
Status affected
Version 75eb6af7acdf566c68d61e98e67ee2f235201c02
Version < 46bc86c833956219bbfd246c1ffd832a479c5199
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/79cd550f8c884523b604fbfa43eb02def74d6224
https://git.kernel.org/stable/c/7a65b41b657b71d5a77861f47dd13eb4bc8e10d0
https://git.kernel.org/stable/c/5b0427ba582d143a364301f825f4e32272f06d2d
https://git.kernel.org/stable/c/d49f6d098ed48775b9d27a9f9c5c220fdf76f102
https://git.kernel.org/stable/c/46bc86c833956219bbfd246c1ffd832a479c5199