Junglewise Threat Intelligence

CVE-2026-46256: Linux Kernel NFS deadlock in LOCALIO direct reclaim

CVE-2026-46256 · Severity: info · Published 2026-06-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's NFS (Network File System) LOCALIO component could cause a system to freeze or crash. This component is used to speed up file access when a computer connects to its own shared folders. Under specific memory pressure conditions, the system can enter a 'deadlock' state where it stops responding while trying to manage its internal memory.

Technical details

A recursion deadlock vulnerability exists in the Linux kernel's NFS LOCALIO optimization. LOCALIO allows NFS loopback mounts to bypass the network stack for READ, WRITE, and COMMIT operations when the client and server are on the same host. However, the implementation was susceptible to a deadlock during direct reclaim: a process could enter the NFS LOCALIO path, trigger a page cache allocation that invokes direct reclaim, which then recurses back into NFS via nfs_writepages. This is resolved by ensuring all page cache allocations in the LOCALIO path use the GFP_NOFS context to prevent the memory allocator from recursing into filesystem code.

Affected products

  • Linux Linux Kernel LOCALIO support introduced in 70ba381e1a43

Timeline

  • 2026-01-07: patched: Initial fix authored by Mike Snitzer
  • 2026-06-03: advisory: CVE-2026-46256 published

References