Executive brief
The Linux kernel's SUNRPC (Sun Remote Procedure Call) subsystem, which handles network-based RPC communication used by services like NFS, contains a memory corruption vulnerability. When RPC requests are deferred twice in rapid succession, the same memory object can be freed twice, causing a system crash or potential code execution. This affects any system running NFS or other RPC-based services.
Technical details
This is a use-after-free/double-free vulnerability in the SUNRPC svc_defer() function (net/sunrpc/svc_xprt.c). The root cause is that when a deferred RPC request is reused, the rq_xprt_ctxt pointer is not consistently cleared before being reused, allowing it to reference already-freed memory. The vulnerable code path occurs when an RPC request is deferred a second time: the transport context pointer from the first deferral remains in the reused svc_deferred_req structure, and when xpo_release_xprt is called, it frees the same context object twice. The vulnerability requires specific RPC usage patterns (rare double-deferral) and affects network-accessible systems running SUNRPC services. The fix ensures rq_xprt_ctxt is always cleared during deferral and adds an assertion to catch the condition.
Affected products
- Linux Linux kernel multiple versions; fix backported to stable kernels including linux-4.4.y through linux-6.x.y series
Timeline
- 2023-05-09: disclosed
- 2023-05-24: patched: Fix backported to stable kernel releases