-

CVE-2026-93212

nfsd: guard nfsd_serv deref in nfsd_file_net_dispose

In the Linux kernel, the following vulnerability has been resolved:

nfsd: guard nfsd_serv deref in nfsd_file_net_dispose

nfsd_file_net_dispose() is the consumer side of l->freeme: the nfsd
service thread loop calls it to drain entries that the filecache
garbage collector and shrinker append via
nfsd_file_dispose_list_delayed().  During per-net teardown,
nn->nfsd_serv is cleared before the filecache laundrette is shut
down, so the service thread can still run a dispose pass that finds
more than eight entries on l->freeme and dereferences a NULL
svc_serv:

    nfsd service thread loop
      nfsd_file_net_dispose(nn)
        if (!list_empty(&l->freeme)) {
            ...
            svc_wake_up(nn->nfsd_serv);   /* nn->nfsd_serv == NULL */
        }

The sibling helper nfsd_file_dispose_list_delayed() already documents
this ordering and caches nn->nfsd_serv into a local before testing it
for NULL.  nfsd_file_net_dispose() was introduced with the same raw
svc_wake_up(nn->nfsd_serv) call and never picked up the guard.

Fix by loading nn->nfsd_serv into a local svc_serv pointer and only
calling svc_wake_up() when it is non-NULL, matching the pattern in
nfsd_file_dispose_list_delayed().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ffb402596147ac583f3464ff5c48feb9423e3838
Version < f4776c1c4b38fbc459420321c8ece87d0f7f95fb
Status affected
Version ffb402596147ac583f3464ff5c48feb9423e3838
Version < 59baf45a06435194005fc5fa9a42d89f77a30432
Status affected
Version ffb402596147ac583f3464ff5c48feb9423e3838
Version < 766170b4fd2daaf5c4d6735560101474e18edab6
Status affected
Version ffb402596147ac583f3464ff5c48feb9423e3838
Version < 9f1ddfc8cb9076592401a611eb3a44d36186d014
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f4776c1c4b38fbc459420321c8ece87d0f7f95fb
https://git.kernel.org/stable/c/59baf45a06435194005fc5fa9a42d89f77a30432
https://git.kernel.org/stable/c/766170b4fd2daaf5c4d6735560101474e18edab6
https://git.kernel.org/stable/c/9f1ddfc8cb9076592401a611eb3a44d36186d014