9.8

CVE-2026-90151

NFSv4: remove callback IDR entry on client allocation failure

In the Linux kernel, the following vulnerability has been resolved:

NFSv4: remove callback IDR entry on client allocation failure

nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it
finishes setting up the client. If any later initialization step fails,
the error path frees the nfs_client directly with nfs_free_client(). That
bypasses nfs_put_client(), which is where the callback IDR entry is
removed during normal teardown.

A failed allocation can therefore leave cb_ident_idr pointing at a freed
nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the
stale pointer and take a reference to it.

Make the callback IDR removal helper callable by the allocation failure
path, and remove the callback identifier before freeing the client.

This was found by a local static-analysis checker for publish-before-free
lifetime bugs and confirmed by manual inspection.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 68c721391b761dbe38d5b0094d2bb6e8489ad92b
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 9bfdd0f591307b5198826a0e7a5b2f35f87acd2d
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 7c4812eb96bdcafb31a65b12f2aa96659429d1d4
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < fc95ca82d5ae598c428ab5a00ae69f8526d59371
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 80b1c3d5a881f7d9081aa9f46da9742878a0f893
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 3f2387e8bfbc4efda5d77c3a11a028d0a119c48f
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < 5891c03e150920618db0e9c4ea2d772abacdcfd1
Status affected
Version f4eecd5da3422e82e88e36c33cbd2595eebcacb1
Version < d05c2007b3d84ccba11dc6e9cb3202768cc72f14
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.38
Status affected
Version 0
Version < 2.6.38
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.531
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/68c721391b761dbe38d5b0094d2bb6e8489ad92b
https://git.kernel.org/stable/c/9bfdd0f591307b5198826a0e7a5b2f35f87acd2d
https://git.kernel.org/stable/c/7c4812eb96bdcafb31a65b12f2aa96659429d1d4
https://git.kernel.org/stable/c/fc95ca82d5ae598c428ab5a00ae69f8526d59371
https://git.kernel.org/stable/c/80b1c3d5a881f7d9081aa9f46da9742878a0f893
https://git.kernel.org/stable/c/3f2387e8bfbc4efda5d77c3a11a028d0a119c48f
https://git.kernel.org/stable/c/5891c03e150920618db0e9c4ea2d772abacdcfd1
https://git.kernel.org/stable/c/d05c2007b3d84ccba11dc6e9cb3202768cc72f14