Executive brief
A race condition vulnerability was identified in the Linux kernel's GFS2 file system component, which manages shared storage in clustered environments. Under specific conditions during a system unmount, the kernel might prematurely free memory while it is still being accessed by the distributed lock manager. This could lead to a system crash or potentially allow an attacker to gain unauthorized control over the system.
Technical details
A race condition exists in the gdlm_put_lock() function within the GFS2 (Global File System 2) subsystem of the Linux kernel. The vulnerability occurs because there is a timing window where the DFL_UNMOUNT flag is set, but the lockspace has not yet been fully released. During this window, the Distributed Lock Manager (DLM) may still trigger asynchronous completion (gdlm_ast) or blocking (gdlm_bast) callbacks. If the glock object is freed prematurely based on the DFL_UNMOUNT flag, these callbacks will dereference the freed memory, resulting in a use-after-free. The fix ensures the glock is only freed if the lockspace has been successfully released (indicated by an -ENODEV error from dlm_unlock). Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.4.284, 4.9.283, 4.14.247, 4.19.207, 5.4.148 and others prior to fix
Timeline
- 2025-12-04: disclosed: Initial CVE publication
- 2025-12-04: advisory
References
- https://git.kernel.org/stable/c/279bde3bbb0ac0bad5c729dfa85983d75a5d7641
- https://git.kernel.org/stable/c/28c4d9bc0708956c1a736a9e49fee71b65deee81
- https://git.kernel.org/stable/c/4913592a3358f6ec366b8346b733d5e2360b08e1
- https://git.kernel.org/stable/c/5fdc1474e678eea1700aa266c0b7c2c96f81dd0d
- https://git.kernel.org/stable/c/64c61b4ac645222fa7b724cef616c1f862a72a40