7.8

CVE-2026-89690

nfsd: defer vfree of compound ops to fix rpc_status UAF

In the Linux kernel, the following vulnerability has been resolved:

nfsd: defer vfree of compound ops to fix rpc_status UAF

The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums out of
args->ops[]. But args->ops is a separate vmalloc buffer freed
synchronously by vfree() in nfsd4_release_compoundargs() at the end
of every compound. The dumpit's rcu_read_lock pins the svc_rqst
struct itself (freed via kfree_rcu), but nothing defers the vfree
of the ops buffer across the RCU grace period. A concurrent compound
completion can therefore free the buffer while the dumpit is reading
it — a use-after-free on vmalloc memory.

The trailing seqcount recheck (smp_load_acquire of rq_status_counter)
cannot undo a load that already retired against freed memory.

Fix by replacing vfree(args->ops) with kvfree_rcu_mightsleep(), which
defers the free until after an RCU grace period. This makes the
existing rcu_read_lock in the dumpit sufficient to protect the read.
The tradeoff is that completed compound ops buffers (up to
200 * sizeof(struct nfsd4_op)) persist in memory slightly longer,
across one grace period, before being reclaimed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 48f72aff24f7a7329209dc6cbc27c869f3e3595c
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 6703199f4d7e7f37d6a726a849eb358e8fae72fb
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 19413ccc45070a7270b9e25c2a258daf7f91de42
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < fca26a3fc19ed02278aa2a150af82d43db0302cb
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/48f72aff24f7a7329209dc6cbc27c869f3e3595c
https://git.kernel.org/stable/c/6703199f4d7e7f37d6a726a849eb358e8fae72fb
https://git.kernel.org/stable/c/19413ccc45070a7270b9e25c2a258daf7f91de42
https://git.kernel.org/stable/c/fca26a3fc19ed02278aa2a150af82d43db0302cb