Executive brief
A memory leak vulnerability was identified in the Linux kernel's Network File System daemon (nfsd). This issue occurs during specific file-opening operations when multiple requests compete for the same resources, potentially leading to a gradual depletion of system memory. If exploited, this could eventually cause system instability or a denial of service for the file sharing server.
Technical details
A memory leak exists in fs/nfsd/nfs4state.c within the Linux kernel's NFS server implementation. The vulnerability is caused by a race condition in find_or_alloc_open_stateowner() where two NFSv4.0 OPEN threads with the same owner string compete. When an unconfirmed owner is encountered and released, the code fails to properly handle a pre-allocated 'new' stateowner pointer, leading to it being overwritten and the associated slab object and name buffer being leaked. The fix introduces a 'goto retry' to ensure pre-allocated objects are reused rather than leaked. The issue affects versions starting from 6.10 and has been patched in stable branches including 6.12.95, 6.18.38, and 7.1.3.
Affected products
- Linux Linux Kernel 6.10 to 7.2-rc1
Timeline
- 2026-05-22: disclosed: Initial patch authored by Jeff Layton
- 2026-07-04: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2026-07-19: advisory: NVD published the CVE record