Executive brief
A vulnerability in the Linux kernel's Network File System daemon (nfsd) could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly clear memory references after releasing access control lists (ACLs), leading to a 'use-after-free' condition. This could disrupt file sharing services or compromise the integrity of the host operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's nfsd component within the NFSv2/v3 ACL implementation. When a failure occurs while retrieving 'acl_default', both 'acl_access' and 'acl_default' are released via 'posix_acl_release'. However, the 'acl_access' pointer in the response structure is not immediately nullified, leaving a dangling pointer. Subsequent calls to 'nfs3svc_release_getacl' attempt to release the same memory again, triggering a reference count underflow and a kernel warning/panic. This issue affects 'fs/nfsd/nfs2acl.c' and 'fs/nfsd/nfs3acl.c'. Patches have been released across multiple stable kernel branches to ensure pointers are cleared after release.
Affected products
- Linux Linux kernel 2.6.13 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.79, 6.7 to 6.12.16, 6.13 to 6.13.4
Timeline
- 2025-01-26: patched: Initial patch authored by Li Lingfeng
- 2025-02-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1fd94884174bd20beb1773990fd3b1aa877688d9
- https://git.kernel.org/stable/c/2e59b2b68782519560b3d6a41dd66a3d01a01cd3
- https://git.kernel.org/stable/c/55d947315fb5f67a35e4e1d3e01bb886b9c6decf
- https://git.kernel.org/stable/c/6f7cfee1a316891890c505563aa54f3476db52fd
- https://git.kernel.org/stable/c/7faf14a7b0366f153284db0ad3347c457ea70136
- https://git.kernel.org/stable/c/8a1737ae42c928384ab6447f6ee1a882510e85fa
- https://git.kernel.org/stable/c/f8d871523142f7895f250a856f8c4a4181614510