Junglewise Threat Intelligence

CVE-2025-21796: Linux Kernel nfsd use-after-free in POSIX ACL handling

CVE-2025-21796 · Severity: high · CVSS 7.8 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Network File System daemon (nfsd) could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly clear memory references after releasing access control lists (ACLs), leading to a 'use-after-free' condition. This could disrupt file sharing services or compromise the integrity of the host operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's nfsd component within the NFSv2/v3 ACL implementation. When a failure occurs while retrieving 'acl_default', both 'acl_access' and 'acl_default' are released via 'posix_acl_release'. However, the 'acl_access' pointer in the response structure is not immediately nullified, leaving a dangling pointer. Subsequent calls to 'nfs3svc_release_getacl' attempt to release the same memory again, triggering a reference count underflow and a kernel warning/panic. This issue affects 'fs/nfsd/nfs2acl.c' and 'fs/nfsd/nfs3acl.c'. Patches have been released across multiple stable kernel branches to ensure pointers are cleared after release.

Affected products

  • Linux Linux kernel 2.6.13 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.79, 6.7 to 6.12.16, 6.13 to 6.13.4

Timeline

  • 2025-01-26: patched: Initial patch authored by Li Lingfeng
  • 2025-02-27: disclosed: CVE published

References

Related threats