Executive brief
A vulnerability exists in the Linux kernel's Network File System (NFS) server component, which is used to share files across a network. A race condition during server shutdown can lead to a system crash or unauthorized memory access. This could allow a local attacker to disrupt operations or potentially gain access to sensitive information on systems running the affected kernel.
Technical details
A use-after-free vulnerability exists in the Linux kernel's nfsd component due to a race condition between writing to 'v4_end_grace' and server shutdown. The root cause is insufficient locking when nfsd4_end_grace() is triggered, which can lead to the 'reclaim_str_hashtbl' being accessed after it has been freed. An attacker with local access to write to the nfsd control files could trigger this race. The fix introduces a 'client_tracking_active' flag and improved spinlock protection to ensure the laundromat work queue does not restart after shutdown has commenced. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel Affected from 7f5ef2e900d9 up to fixed versions in stable branches
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later versions based on affected Linux kernels
Timeline
- 2025-12-13: disclosed: Initial patch authored by NeilBrown
- 2026-01-17: patched: Patch committed to stable tree
- 2026-01-23: advisory: CVE-2026-22980 published
References
- https://git.kernel.org/stable/c/06600719d0f7a723811c45e4d51f5b742f345309
- https://git.kernel.org/stable/c/2857bd59feb63fcf40fe4baf55401baea6b4feb4
- https://git.kernel.org/stable/c/34eb22836e0cdba093baac66599d68c4cd245a9d
- https://git.kernel.org/stable/c/53f07d095e7e680c5e4569a55a019f2c0348cdc6
- https://git.kernel.org/stable/c/ba4811c8b433bfa681729ca42cc62b6034f223b0
- https://git.kernel.org/stable/c/ca97360860eb02e3ae4ba42c19b439a0fcecbf06
- https://git.kernel.org/stable/c/e8bfa2401d4c51eca6e48e9b33c798828ca9df61