Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server component can lead to system instability or crashes. The issue occurs when the server incorrectly manages file references during certain file-sharing operations, causing memory to leak. Over time, or during a server shutdown, this can trigger a critical system error (kernel panic), resulting in a denial of service for users relying on the file server.
Technical details
A reference counting vulnerability exists in the nfsd4_add_rdaccess_to_wrdeleg() function within the Linux kernel's NFS server (nfsd). The function unconditionally overwrites the O_RDONLY file descriptor pointer without releasing existing references if a client already has a read-access open operation in progress. Furthermore, it incorrectly shared a single reference between two pointers (fi_fds and fi_rdeleg_file), leading to orphaned references when the delegation is released. An attacker or a series of specific client operations can trigger these leaks, causing open conflicts and eventually a kernel BUG() in kmem_cache_destroy() during server shutdown due to unpurged file cache objects. Patches have been released for stable kernel branches including 6.18.4 and 6.19.
Affected products
- Linux Linux Kernel 6.17 to 6.18.4
Timeline
- 2025-12-01: other: Fix authored by Chuck Lever
- 2026-01-08: patched: Patch committed to stable tree
- 2026-01-13: disclosed: CVE published