Junglewise Threat Intelligence

CVE-2026-31402: Linux Kernel nfsd heap overflow in NFSv4.0 LOCK replay cache

CVE-2026-31402 · Severity: critical · CVSS 9.8 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Network File System (NFS) server could allow a remote attacker to crash the system or potentially execute unauthorized code. The issue exists in how the server handles file locking requests, specifically when a request is denied and the server attempts to record the event. An attacker using two coordinated connections can trigger a memory corruption event that disrupts operations or compromises the security of the host server.

Technical details

A slab-out-of-bounds write vulnerability exists in the Linux kernel's NFS server (nfsd) within the NFSv4.0 LOCK replay cache. The replay cache utilizes a fixed 112-byte inline buffer (rp_ibuf) which is insufficient for LOCK denied responses that include conflicting lock owners up to 1024 bytes. When a LOCK operation is denied, nfsd4_encode_operation() calls read_bytes_from_xdr_buf() to copy the encoded response into this buffer without performing bounds checking. An unauthenticated remote attacker can exploit this by using two cooperating NFSv4.0 clients: one to set a lock with a maximum-length owner string, and another to request a conflicting lock. This triggers a heap overflow of up to 944 bytes. Patches have been released for various stable kernel branches to implement length validation before copying to the replay buffer.

Affected products

  • Linux Linux Kernel 2.6.12-rc2 to 5.10.253, 5.11 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10

Timeline

  • 2026-02-24: other: Vulnerability fixed in upstream source code
  • 2026-04-03: disclosed: CVE published
  • 2026-04-03: advisory

References

Related threats