Executive brief
A vulnerability was identified in the Linux kernel's Network File System (NFS) server component. When the system fails to set a specific type of file lock (a lease) during layout allocation, it incorrectly cleans up internal memory structures. This can lead to a system crash or instability when the kernel later tries to access that memory, potentially impacting the availability of the file server.
Technical details
A use-after-free vulnerability exists in fs/nfsd/nfs4layouts.c within the Linux kernel. The function nfs4_alloc_stid() publishes a new stateid into the client stateid IDR before returning to nfsd4_alloc_layout_stateid(). If a subsequent call to nfsd4_layout_setlease() fails, the error path incorrectly frees the layout stateid using kmem_cache_free() without removing the corresponding entry from the IDR. This leaves a dangling pointer in the IDR table that can be dereferenced by subsequent IDR walkers, such as during client teardown or state inspection. Additionally, the fix addresses an uninitialized delayed_work structure (ls_fence_work) that could be accessed during the corrected teardown path. The issue has been resolved by ensuring proper IDR removal via nfs4_put_stid() and reordering initialization.
Affected products
- Linux Linux Kernel 4.0 to 6.13
Timeline
- 2026-05-18: other: Patch authored
- 2026-07-19: disclosed: CVE published