Executive brief
The Linux kernel's NFS server (nfsd) component contains a use-after-free vulnerability in the local I/O code path. An attacker with local access can manipulate memory timing to cause the kernel to dereference freed memory objects, potentially leading to a denial of service or privilege escalation. This affects systems running vulnerable kernel versions that use NFS with local I/O optimizations.
Technical details
The vulnerability is a use-after-free in nfsd_open_local_fh() caused by a race condition between CPU cores. nfsd_file objects are freed via call_rcu() and the slab page backing them becomes reclaimable after the RCU grace period elapses. The vulnerable code path calls cmpxchg() to load a pointer and then calls nfsd_file_get() (refcount_inc_not_zero) without holding rcu_read_lock(), creating a window where another CPU can free the nfsd_file object, recycle the slab page, and cause the subsequent refcount operation to dereference recycled memory. The attacker gains the ability to make the kernel operate on freed memory regions containing attacker-controllable data. The fix is to acquire rcu_read_lock() immediately before the cmpxchg and hold it through all exit paths of the critical section to prevent slab recycling during the vulnerable window.
Affected products
- Linux Linux kernel versions with nfsd local I/O optimization prior to the fix
Timeline
- 2026-09-11: disclosed
- patched: Fix involves adding rcu_read_lock/rcu_read_unlock around cmpxchg operation in nfsd_open_local_fh()