7.1

CVE-2026-93229

nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry

In the Linux kernel, the following vulnerability has been resolved:

nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry

The hand-rolled seqcount-like protocol in nfsd_nl_rpc_status_get_dumpit()
is missing a read memory barrier (smp_rmb) before its second counter
check.  The standard kernel read_seqcount_retry() includes smp_rmb()
to ensure that all data reads complete before the counter is re-checked.

Without this barrier, on weakly-ordered architectures (ARM, POWER),
the CPU may reorder field reads past the second counter check, making
the retry logic ineffective: it could observe a consistent counter pair
while reading fields that have been concurrently modified by the writer.

Add smp_rmb() before the second counter check to order the field reads
ahead of it, matching the barrier semantics of the standard seqcount
read-side.  The begin-side smp_load_acquire() already pairs with the
smp_store_release() in nfsd_dispatch(); with the smp_rmb() now ordering
the field reads, the retry check no longer needs acquire semantics and
reads the counter with a plain READ_ONCE(), as read_seqcount_retry()
does.

[ cel: Use READ_ONCE instead of smp_load_acquire() ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < f501f2f4ec1d2dfe39e21c98630314074a9b30b0
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 1aea0482b98ecd7d0249204665f2ad4ad517f66b
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < 9b5f6475006cd8e3b5b99b8eb3cd74dbb1ce9df8
Status affected
Version bd9d6a3efa9709e653aafbeb859289feccb8e70c
Version < a71f161a857117e8e0264deb7d14fff5c98adcf5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f501f2f4ec1d2dfe39e21c98630314074a9b30b0
https://git.kernel.org/stable/c/1aea0482b98ecd7d0249204665f2ad4ad517f66b
https://git.kernel.org/stable/c/9b5f6475006cd8e3b5b99b8eb3cd74dbb1ce9df8
https://git.kernel.org/stable/c/a71f161a857117e8e0264deb7d14fff5c98adcf5