Executive brief
The Linux kernel's NFSD (Network File System Daemon) has a defect in its module initialization sequence where debugfs files are registered before memory slab caches are allocated. If slab allocation fails during module startup, the early error return leaves orphaned debugfs entries with dangling pointers to freed kernel code. This can lead to kernel crashes or memory corruption when those orphaned debugfs files are accessed after the module is unloaded.
Technical details
The vulnerability is a use-after-free condition caused by improper initialization ordering in the NFSD module. The nfsd_debugfs_init() function is called before nfsd4_init_slabs() in init_nfsd(). If slab initialization fails, the bare "return retval" statement bypasses nfsd_debugfs_exit(), leaving orphan debugfs files with stale function pointers (fops) into freed module text. The fix reorders initialization so that debugfs is set up only after slabs succeed, and updates error unwinding to follow reverse-initialization (LIFO) order. The attack vector is local (requires access to /sys/kernel/debug/nfsd on the affected system), and no authentication is needed to trigger the condition if slab allocation fails. A privileged local attacker could potentially exploit this to cause denial of service or memory corruption.
Affected products
- Linux Linux kernel Multiple versions affected; patch available in mainline and stable trees
Timeline
- 2026-09-11: disclosed: Published to NVD
- 2026-06-11: patched: Patch committed by Jeff Layton (commit 2c390c8a1764d67095fe444401861fac4c049362)
- 2026-09-07: patched: Backport to stable kernels