Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component could allow a local user to cause a system instability or crash. The issue occurs when the system fails to properly release internal resources during certain file mapping operations. This could lead to a denial-of-service condition, impacting the availability of the server and any connected services.
Technical details
A reference counting bug exists in the Linux kernel's nfsd (NFS server) in the idmap_id_to_name function within fs/nfsd/nfs4idmap.c. When idmap_lookup triggers a successful lookup_fn, it increments a cache reference via cache_get. However, if a subsequent call to xdr_reserve_space fails (returning NULL) due to insufficient buffer space, the function returns early without calling the corresponding cache_put. This leads to a reference count leak. An attacker with local access could potentially exploit this to cause resource exhaustion or a denial-of-service. The issue has been patched across multiple stable kernel branches by ensuring cache_put is called in the error path.
Affected products
- Linux Linux Kernel 3.16 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2
Timeline
- 2024-10-21: disclosed
- 2024-10-21: advisory
References
- https://git.kernel.org/stable/c/3e8081ebff12bec1347deaceb6bce0765cce54df
- https://git.kernel.org/stable/c/81821617312988096f5deccf0f7da6f888e98056
- https://git.kernel.org/stable/c/8d0765f86135e27f0bb5c950c136495719b4c834
- https://git.kernel.org/stable/c/9803ab882d565a8fb2dde5999d98866d1c499dfd
- https://git.kernel.org/stable/c/9f03f0016ff797932551881c7e06ae50e9c39134
- https://git.kernel.org/stable/c/a1afbbb5276f943ad7173d0b4c626b8c75a260da
- https://git.kernel.org/stable/c/c6b16e700cf4d959af524bd9d3978407ff7ce462