Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component could allow an attacker to cause a system crash or potentially corrupt data. The issue occurs when the server fails to properly clean up internal tracking information after a client reboots, leading to memory management errors. This could result in a complete denial of service for the affected server, impacting business operations and data availability.
Technical details
A vulnerability exists in the Linux kernel NFSD implementation due to improper handling of 'copynotify' stateids within the nfs4_free_ol_stateid() function. When a client reboots and initiates a new session, the server expires the previous state; however, if a COPY_NOTIFY operation was active, its associated stateid remains in a list linked to the now-freed parent stateid. This leads to list corruption when the 'laundromat' process later attempts to free the orphaned copynotify state. An attacker with network access and basic authenticated file access (PR:L) can trigger this condition to cause a kernel panic (Oops) or potentially achieve further memory corruption. The fix ensures that associated copynotify stateids are explicitly freed when the parent open-owner stateid is released.
Affected products
- Linux Linux Kernel 624322f1adc5 to 935a2dc8928670bb2c37e21025331e61ec48ccf4
Timeline
- 2025-10-14: disclosed: Initial patch submission by Olga Kornievskaia
- 2025-11-24: patched: Patch committed to stable kernel tree
- 2025-12-06: advisory: CVE-2025-40273 published
References
- https://git.kernel.org/stable/c/29fbb3ad4018ca2b0988fbac76f4c694cc6d7e66
- https://git.kernel.org/stable/c/4aa17144d5abc3c756883e3a010246f0dba8b468
- https://git.kernel.org/stable/c/839f56f626723f36904764858467e7a3881b975d
- https://git.kernel.org/stable/c/935a2dc8928670bb2c37e21025331e61ec48ccf4
- https://git.kernel.org/stable/c/b114996a095da39e38410a0328d4a8aca8c36088
- https://git.kernel.org/stable/c/d7be15a634aa3874827d0d3ea47452ee878b8df7
- https://git.kernel.org/stable/c/f67ad9b33b0e6f00d2acc67cbf9cfa5c756be5fb