Executive brief
A vulnerability in the Linux kernel's Network File System (NFS) server could allow a remote attacker to crash the system or potentially execute unauthorized code. The issue exists in how the server handles file locking requests, specifically when a request is denied and the server attempts to record the event. An attacker using two coordinated connections can trigger a memory corruption event that disrupts operations or compromises the security of the host server.
Technical details
A slab-out-of-bounds write vulnerability exists in the Linux kernel's NFS server (nfsd) within the NFSv4.0 LOCK replay cache. The replay cache utilizes a fixed 112-byte inline buffer (rp_ibuf) which is insufficient for LOCK denied responses that include conflicting lock owners up to 1024 bytes. When a LOCK operation is denied, nfsd4_encode_operation() calls read_bytes_from_xdr_buf() to copy the encoded response into this buffer without performing bounds checking. An unauthenticated remote attacker can exploit this by using two cooperating NFSv4.0 clients: one to set a lock with a maximum-length owner string, and another to request a conflicting lock. This triggers a heap overflow of up to 944 bytes. Patches have been released for various stable kernel branches to implement length validation before copying to the replay buffer.
Affected products
- Linux Linux Kernel 2.6.12-rc2 to 5.10.253, 5.11 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10
Timeline
- 2026-02-24: other: Vulnerability fixed in upstream source code
- 2026-04-03: disclosed: CVE published
- 2026-04-03: advisory
References
- https://git.kernel.org/stable/c/0f0e2a54a31a7f9ad2915db99156114872317388
- https://git.kernel.org/stable/c/5133b61aaf437e5f25b1b396b14242a6bb0508e2
- https://git.kernel.org/stable/c/8afb437ea1f70cacb4bbdf11771fb5c4d720b965
- https://git.kernel.org/stable/c/ae8498337dfdfda71bdd0b807c9a23a126011d76
- https://git.kernel.org/stable/c/c9452c0797c95cf2378170df96cf4f4b3bca7eff
- https://git.kernel.org/stable/c/dad0c3c0a8e5d1d6eb0fc455694ce3e25e6c57d0
- https://git.kernel.org/stable/c/f9fcb4441f6c02bb20c2eb340101e27dfe23607c