9.8

CVE-2026-89485

lockd: pin next file across nlm_inspect_file lock-drop

In the Linux kernel, the following vulnerability has been resolved:

lockd: pin next file across nlm_inspect_file lock-drop

nlm_traverse_files() pins the current file with f_count++ across
a mutex_unlock for nlm_inspect_file(), but nothing pins the saved
next pointer.  A concurrent nlm_release_file() can kfree the next
file during the unlock window, and the iterator dereferences freed
memory on the next loop step.

Pin both current and next before the lock-drop.  Advance by
swapping the pinned cursors at the end of each iteration so next
is always held alive across the unlock.

Always call nlm_file_release() after dropping the iteration pin,
regardless of whether the file matched the predicate.  Use
nlm_file_inuse(), which does a live walk of the inode lock list,
rather than the cached f_locks field, so skipped files that never
ran nlm_inspect_file() are evaluated correctly.

Because every file in a hash bucket is now pinned and released,
files skipped by the is_failover_file predicate that have no
locks, blocks, shares, or external references are deleted during
traversal.  The old code never evaluated skipped files for
cleanup.  The new behavior is intentional: such files are stale
and should not persist in the table.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < e3c413f789eaf0170275c7eba523ead73d963f30
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < 08a455f87b14c7ff22ae3fdadda62a796a3a5572
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < 550c19222c7132c888e23c9d89079ba1c9bc4cca
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < 350087f231c11efcd288c310707c40eab63ca583
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < c24bdb7df2f34bdc38ca8a73796f5acb40f1830c
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < 41f0a6d31615fcae261bf28a0aa50050dc93a401
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < e999a88133654c6dfc68487fb49da5f20dfa2d4f
Status affected
Version 01df9c5e918ae5559f2d96da0143f8bfbb9e6171
Version < 526c49cff3f72c3ec74752016380c7567040581b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.18
Status affected
Version 0
Version < 2.6.18
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c24bdb7df2f34bdc38ca8a73796f5acb40f1830c
https://git.kernel.org/stable/c/41f0a6d31615fcae261bf28a0aa50050dc93a401
https://git.kernel.org/stable/c/e999a88133654c6dfc68487fb49da5f20dfa2d4f
https://git.kernel.org/stable/c/526c49cff3f72c3ec74752016380c7567040581b
https://git.kernel.org/stable/c/08a455f87b14c7ff22ae3fdadda62a796a3a5572
https://git.kernel.org/stable/c/350087f231c11efcd288c310707c40eab63ca583
https://git.kernel.org/stable/c/550c19222c7132c888e23c9d89079ba1c9bc4cca
https://git.kernel.org/stable/c/e3c413f789eaf0170275c7eba523ead73d963f30