8.1

CVE-2026-89682

nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventing the shrinker and GC worker from
bearing the cost of closing files (see ffb402596147).  However, the
queue lives in a separately-allocated struct nfsd_fcache_disposal that
is freed by nfsd_free_fcache_disposal_net() during per-net teardown.
The global shrinker, laundrette, and fsnotify callbacks can still be
inside nfsd_file_dispose_list_delayed() dereferencing that pointer,
causing a use-after-free.

Inline the spinlock and freeme list directly into struct nfsd_net (as
fcache_dispose_lock and fcache_dispose_list), eliminating the separately
allocated struct nfsd_fcache_disposal entirely.  These fields now have
the same lifetime as the net namespace itself, so there is no dangling
pointer to chase.

nfsd_file_cache_start_net() now just initializes the inline fields and
cannot fail due to allocation.  nfsd_file_cache_shutdown_net() drains
the inline list directly instead of freeing a separate struct.  The
alloc/free helpers are removed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1463b38e7cf34d4cc60f41daff459ad807b2e408
Version < ba0ee9e04b7a0356c28d5a2fe445db675d24e572
Status affected
Version 1463b38e7cf34d4cc60f41daff459ad807b2e408
Version < cadc9036d5a8209f89e7026ddba7cfb1c716b03c
Status affected
Version 1463b38e7cf34d4cc60f41daff459ad807b2e408
Version < bbf13732f74351d21c5e0e8dd9bd8e1c48dc35d4
Status affected
Version e8f923e1e9fcc0832a12c8a2461792e5a9544c03
Status affected
Version 3bc94fb44f10ef852723e1aeaac6794c5ab16aec
Status affected
Version 5.10.220
Version < 5.11
Status affected
Version 5.15.154
Version < 5.16
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.17
Status affected
Version 0
Version < 5.17
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.333
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ba0ee9e04b7a0356c28d5a2fe445db675d24e572
https://git.kernel.org/stable/c/cadc9036d5a8209f89e7026ddba7cfb1c716b03c
https://git.kernel.org/stable/c/bbf13732f74351d21c5e0e8dd9bd8e1c48dc35d4