-

CVE-2026-90039

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,
walks the NFSv4 client hash tables to revoke open state and cancel
async COPY operations.  All three handlers gate that walk on
nn->nfsd_serv, but a listener added via portlist or netlink
listener_set sets nn->nfsd_serv before any nfsd thread starts.
nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the
walkers dereference a NULL table.  A local administrator with
CAP_SYS_ADMIN can crash the kernel this way without ever starting the
server.

nn->nfsd_serv is set when the service is created, which precedes
table allocation.  NFSD_NET_UP instead brackets the window where the
tables are live: set at the end of nfsd_startup_net() and cleared in
nfsd_shutdown_net() after they are freed, both under nfsd_mutex.
Gating the three unlock paths on NFSD_NET_UP fixes the startup-time
NULL dereference while preserving the earlier post-shutdown
use-after-free fix.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1ac3629bf012592cb0320e52a1cceb319a05ad17
Version < 73bf459d696ecf207a9037bf9bb70c51a459469e
Status affected
Version 1ac3629bf012592cb0320e52a1cceb319a05ad17
Version < 104a51265042b4424085741c963cb858ac29ec0b
Status affected
Version 1ac3629bf012592cb0320e52a1cceb319a05ad17
Version < 0146467a2fce845cb6629979c3e9c58dd3d3a6a3
Status affected
Version 1ac3629bf012592cb0320e52a1cceb319a05ad17
Version < 2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.083
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/104a51265042b4424085741c963cb858ac29ec0b
https://git.kernel.org/stable/c/0146467a2fce845cb6629979c3e9c58dd3d3a6a3
https://git.kernel.org/stable/c/2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378
https://git.kernel.org/stable/c/73bf459d696ecf207a9037bf9bb70c51a459469e