Junglewise Threat Intelligence

CVE-2026-22980: Linux Kernel nfsd use-after-free in v4_end_grace

CVE-2026-22980 · Severity: high · CVSS 7.8 · Published 2026-01-23

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's Network File System (NFS) server component, which is used to share files across a network. A race condition during server shutdown can lead to a system crash or unauthorized memory access. This could allow a local attacker to disrupt operations or potentially gain access to sensitive information on systems running the affected kernel.

Technical details

A use-after-free vulnerability exists in the Linux kernel's nfsd component due to a race condition between writing to 'v4_end_grace' and server shutdown. The root cause is insufficient locking when nfsd4_end_grace() is triggered, which can lead to the 'reclaim_str_hashtbl' being accessed after it has been freed. An attacker with local access to write to the nfsd control files could trigger this race. The fix introduces a 'client_tracking_active' flag and improved spinlock protection to ensure the laundromat work queue does not restart after shutdown has commenced. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel Affected from 7f5ef2e900d9 up to fixed versions in stable branches
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later versions based on affected Linux kernels

Timeline

  • 2025-12-13: disclosed: Initial patch authored by NeilBrown
  • 2026-01-17: patched: Patch committed to stable tree
  • 2026-01-23: advisory: CVE-2026-22980 published

References

Related threats