Executive brief
A vulnerability was identified in the Linux kernel's Network File System (NFS) component that could lead to a system crash or unauthorized memory access. The issue occurs during specific high-speed data writing operations where the system incorrectly handles internal tracking of data requests. This could allow a local user to destabilize the system or potentially gain elevated privileges, impacting the reliability and security of servers using NFS for storage.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel NFS client's direct write path due to a double-completion of 'nfs_direct_request'. When asynchronous commit requests are submitted, a race condition allows one request to complete before the next is submitted, leading to multiple calls to 'nfs_direct_write_complete' and a subsequent refcount underflow. This occurs because the 'nfs_direct_commit_schedule' function lacked proper 'nfs_commit_begin' and 'nfs_commit_end' wrapping to synchronize completion handling. An attacker with local access could exploit this to cause a kernel panic or execute arbitrary code. The issue has been patched in various stable branches including 5.10.215, 5.15.154, 6.1.84, 6.6.24, 6.7.12, and 6.8.3.
Affected products
- Linux Linux Kernel up to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3
Timeline
- 2024-03-01: patched: Initial patch authored by Josef Bacik
- 2024-05-01: advisory: CVE-2024-26958 published in NVD
References
- https://git.kernel.org/stable/c/17f46b803d4f23c66cacce81db35fef3adb8f2af
- https://git.kernel.org/stable/c/1daf52b5ffb24870fbeda20b4967526d8f9e12ab
- https://git.kernel.org/stable/c/3abc2d160ed8213948b147295d77d44a22c88fa3
- https://git.kernel.org/stable/c/4595d90b5d2ea5fa4d318d13f59055aa4bf3e7f5
- https://git.kernel.org/stable/c/6cd3f13aaa62970b5169d990e936b2e96943bc6a
- https://git.kernel.org/stable/c/80d24b308b7ee7037fc90d8ac99f6f78df0a256f
- https://git.kernel.org/stable/c/cf54f66e1dd78990ec6b32177bca7e6ea2144a95