Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component could allow a local attacker to cause a system crash or potentially execute unauthorized actions. The issue occurs when the system shuts down NFS services while certain background maintenance tasks are still running, leading to memory corruption. This could result in a loss of system availability or unauthorized access to sensitive data.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's NFSD (NFS server) implementation within the nfs4_state_shutdown_net function. The root cause is a race condition where nfsd_shrinker_work is cancelled using non-synchronous mode (cancel_work) instead of synchronous mode (cancel_work_sync). If the nfsd_client_shrinker is running concurrently during service shutdown (e.g., when reducing thread counts to zero), it may attempt to access or destroy nfs4_client objects and associated file cache slabs after they have already been released by the shutdown process. This leads to 'objects remaining' warnings in kmem_cache_shutdown and subsequent UAF errors. The vulnerability is reachable by a local user with sufficient privileges to modify NFSD thread settings via /proc/fs/nfsd/threads.
Affected products
- Linux Linux Kernel 5.10.220 to 5.15, 5.15.154 to 6.1, 6.2 to 6.6.59, 6.7 to 6.11.6, 6.12-rc1 to 6.12-rc4
Timeline
- 2024-10-21: other: Patch submitted by developer
- 2024-11-05: advisory: CVE published
References
- https://git.kernel.org/stable/c/36775f42e039b01d4abe8998bf66771a37d3cdcc
- https://git.kernel.org/stable/c/5ade4382de16c34d9259cb548f36ec5c4555913c
- https://git.kernel.org/stable/c/add1df5eba163a3a6ece11cb85890e2e410baaea
- https://git.kernel.org/stable/c/d5ff2fb2e7167e9483846e34148e60c0c016a1f6
- https://git.kernel.org/stable/c/f67138dd338cb564ade7d3755c8cd4f68b46d397
- https://git.kernel.org/stable/c/f965dc0f099a54fca100acf6909abe52d0c85328
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html