9.8

CVE-2026-90037

NFSD: Prevent client use-after-free during close_lru reaping

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during close_lru reaping

An nfs4_openowner left on nn->close_lru after its final CLOSE keeps
its last closed stateid in oo_last_closed_stid, holding only a raw
pointer to its nfs4_client. The laundromat reaps timed-out entries,
drops nn->client_lock, and calls nfs4_put_stid(), which dereferences
the client through cl_lock. Nothing pins the client across that
window, so a concurrent force_expire_client() can free it and
nfs4_put_stid() reads freed memory. __destroy_client() hits the same
race, walking clp->cl_openowners without cl_lock.

Pin the client with cl_rpc_users before dropping client_lock, and
skip clients already expiring. __destroy_client() then cleans up its
own close_lru entries through release_last_closed_stateid(), so
teardown no longer races the laundromat.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 217526e7ecc9f6f243e976772e81eab7ab986a4c
Version < 0763482227822f7343557f086afc382086d56c4c
Status affected
Version 217526e7ecc9f6f243e976772e81eab7ab986a4c
Version < 83dd59ac1c3455c2c7d8ddb582d980a13199b9b3
Status affected
Version 217526e7ecc9f6f243e976772e81eab7ab986a4c
Version < e57a9ed34ea8c17e831de59b8f1a6b2d80d347a1
Status affected
Version 217526e7ecc9f6f243e976772e81eab7ab986a4c
Version < 2330b788d732f43668b965b3105b37ceb276dfea
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.389
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/83dd59ac1c3455c2c7d8ddb582d980a13199b9b3
https://git.kernel.org/stable/c/e57a9ed34ea8c17e831de59b8f1a6b2d80d347a1
https://git.kernel.org/stable/c/2330b788d732f43668b965b3105b37ceb276dfea
https://git.kernel.org/stable/c/0763482227822f7343557f086afc382086d56c4c