Executive brief
The Linux kernel's Network File System (NFS) implementation contains a bug in its direct I/O (O_DIRECT) request retransmission logic. When the kernel needs to resend a write request to an NFS server, it may fail to properly reassemble the request fragments, potentially leading to data corruption or loss on the server side. This affects systems that use NFS with direct I/O operations, commonly seen in high-performance storage and database environments.
Technical details
The vulnerability exists in the NFS O_DIRECT retransmission path (fs/nfs/direct.c). When a request needs to be retransmitted after the server has already partially processed it, the kernel must rejoin subrequest pages back into the main request. However, if the head request was not on the commit list (because the server wrote it synchronously), it was not being added back to the retransmission list, causing data inconsistency during retransmit. The fix adds a nfs_direct_add_page_head() function that ensures the head request is properly added to retransmission lists, mirroring the logic of nfs_cancel_remove_inode(). The patch applies to the O_DIRECT code path and requires the kernel to have the vulnerable code introduced in commit ed5d588fe47f.
Affected products
- Linux Linux Kernel Versions from commit ed5d588fe47f onwards (approximately Linux 5.10 and later)
Timeline
- 2023-08-19: disclosed: Patch authored by Trond Myklebust
- 2023-09-19: patched: Patch merged to stable kernel trees