Executive brief
A race condition vulnerability was identified in the Linux kernel's Network File System (NFS) implementation. NFS is a protocol used to share files across a network, allowing users to access remote files as if they were local. An exploit could allow a local user to cause a system crash or potentially corrupt data by triggering a timing conflict during file write operations.
Technical details
A race condition exists in the Linux kernel NFS client within the nfs_lock_and_join_requests() and nfs_inode_remove_request() functions. The vulnerability stems from improper synchronization where a request could be removed from a mapping after initial testing but before the page group lock is acquired. This occurs because the caller of nfs_inode_remove_request() does not necessarily hold the lock on the page group head. An attacker with local access could exploit this race to cause a kernel panic or memory corruption. The fix involves acquiring the page group lock earlier in the request joining process and holding it throughout the removal operation. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel bd37d6fce184 to 0ff42a32784e0f2cb46a46da8e9f473538c13e1b
- Siemens SIMATIC CN 4100 V5.0 and earlier
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and earlier
Timeline
- 2025-08-16: patched: Initial patch authored by Trond Myklebust
- 2025-09-05: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/0ff42a32784e0f2cb46a46da8e9f473538c13e1b
- https://git.kernel.org/stable/c/181feb41f0b268e6288bf9a7b984624d7fe2031d
- https://git.kernel.org/stable/c/202a3432d21ac060629a760fff3b0a39859da3ea
- https://git.kernel.org/stable/c/76d2e3890fb169168c73f2e4f8375c7cc24a765e
- https://git.kernel.org/stable/c/92278ae36935a54e65fef9f8ea8efe7e80481ace
- https://git.kernel.org/stable/c/c32e3c71aaa1c1ba05da88605e2ddd493c58794f
- https://git.kernel.org/stable/c/f230d40147cc37eb3aef4d50e2e2c06ea73d9a77