-
CVE-2026-89661
- EPSS 0.19%
- Veröffentlicht 11.09.2026 19:45:49
- Zuletzt bearbeitet 11.09.2026 20:19:52
- Erkennungen
NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem Writing a filesystem path to /proc/fs/nfsd/unlock_filesystem runs nfsd4_cancel_copy_by_sb() before nfsd_mutex is held and before the handler confirms that nn->nfsd_serv is set. Once nfsd has shut down, nfs4_state_destroy_net() has freed nn->conf_id_hashtbl but left the pointer intact, so the cancel helper iterates freed slab memory as an array of struct list_head and then dereferences a bogus nfs4_client when it takes clp->async_lock. A local administrator holding CAP_SYS_ADMIN can reach this use-after-free by stopping the server and then writing to unlock_filesystem; KASAN reports a slab-use-after-free read in nfsd4_cancel_copy_by_sb(). nfsd4_revoke_states() walks the same state tables and for that reason already runs only under nfsd_mutex with nn->nfsd_serv confirmed present. Move the async COPY cancel into that protected section so every NFSv4 state-table walker on this path observes a running server. Async copies exist only while the server runs, so gating the cancel on nn->nfsd_serv loses nothing.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
3daab3112f039cf849f96764019b096bb0a39d04
Version <
0c1a755b7212e0835398d4df5e782ea85ccd7476
Status
affected
Version
3daab3112f039cf849f96764019b096bb0a39d04
Version <
292d915d3ba6fd15eeb88351fa10581683073109
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.0
Status
affected
Version
0
Version <
7.0
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.087 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/0c1a755b7212e0835398d4df5e782ea85ccd7476
https://git.kernel.org/stable/c/292d915d3ba6fd15eeb88351fa10581683073109