CVE-2026-89661

Summary

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent post-shutdown use-after-free in unlock_filesystem

Writing a filesystem path to /proc/fs/nfsd/unlock_filesystem runs nfsd4_cancel_copy_by_sb() before nfsd_mutex is held and before the handler confirms that nn->nfsd_serv is set. Once nfsd has shut down, nfs4_state_destroy_net() has freed nn->conf_id_hashtbl but left the pointer intact, so the cancel helper iterates freed slab memory as an array of struct list_head and then dereferences a bogus nfs4_client when it takes clp->async_lock. A local administrator holding CAP_SYS_ADMIN can reach this use-after-free by stopping the server and then writing to unlock_filesystem; KASAN reports a slab-use-after-free read in nfsd4_cancel_copy_by_sb().

nfsd4_revoke_states() walks the same state tables and for that reason already runs only under nfsd_mutex with nn->nfsd_serv confirmed present. Move the async COPY cancel into that protected section so every NFSv4 state-table walker on this path observes a running server. Async copies exist only while the server runs, so gating the cancel on nn->nfsd_serv loses nothing.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3daab3112f039cf849f96764019b096bb0a39d04 < 0c1a755b7212e0835398d4df5e782ea85ccd7476affected
LinuxLinux3daab3112f039cf849f96764019b096bb0a39d04 < 292d915d3ba6fd15eeb88351fa10581683073109affected
LinuxLinux7.0affected
LinuxLinux0 < 7.0unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References