9.8

CVE-2026-90036

NFSD: Prevent client use-after-free during blocked-lock reaping

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during blocked-lock reaping

A bare lock owner -- its only remaining reference a blocked lock on
nn->blocked_locks_lru -- holds a raw pointer to its nfs4_client but
no reference keeping the client alive. When the per-net laundromat
reaps such a lock, freeing the nbl drops the owner reference
held through flc_owner, and the final nfs4_put_stateowner()
takes the client's cl_lock. Because the laundromat detaches the
nbl first, __destroy_client() no longer finds it, so a concurrent
force_expire_client() can free the client before nfs4_put_stateowner()
runs, dereferencing cl_lock in freed memory.

Pin the client with cl_rpc_users before dropping
nn->blocked_locks_lock, and skip clients already expiring, whose
blocked locks __destroy_client() frees while holding an owner
reference. Take nn->client_lock outside nn->blocked_locks_lock.
Every other site holds nn->blocked_locks_lock as a leaf, acquiring
no further lock, so placing nn->client_lock outside it cannot form
a lock-order cycle.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b
Version < 7081224a59a0ca4edcd62c068588f4d900199a18
Status affected
Version 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b
Version < cd489b03587378645fe0d20142a33f1ed60bac98
Status affected
Version 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b
Version < 6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0
Status affected
Version 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b
Version < 9026932ac8be4d0ae01db47f23619a98cc57b671
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.9
Status affected
Version 0
Version < 4.9
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.393
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cd489b03587378645fe0d20142a33f1ed60bac98
https://git.kernel.org/stable/c/6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0
https://git.kernel.org/stable/c/9026932ac8be4d0ae01db47f23619a98cc57b671
https://git.kernel.org/stable/c/7081224a59a0ca4edcd62c068588f4d900199a18