Executive brief
A memory reference leak in the Linux kernel's NFS localio feature can cause file descriptors and network namespaces to be pinned in memory when certain race conditions occur during file handle operations. This prevents proper cleanup and teardown of NFS server resources, potentially causing system resource exhaustion or denial of service when affected.
Technical details
The vulnerability is a reference leak (resource leak) in the NFS/localio subsystem of the Linux kernel. When nfs_uuid_add_file() races with nfs_uuid_put() during UUID teardown and returns -ENXIO without publishing the nfl->nfs_uuid pointer, the error path in nfsd_open_local_fh() fails to release two held references: a caller-owned nfsd_file reference and an embedded nfsd_net reference. The close path cannot release these references because the nfs_uuid pointer was never set. This causes nfsd_file structures (and their underlying file, dentry, and inode) and nfsd_net references to leak, pinning resources and blocking namespace teardown. The fix releases both references via an existing helper before returning -ENXIO and properly balances the three nfsd_net_try_get() increments on the error branch.
Affected products
- Linux Linux kernel <5.15
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fix committed to kernel resolving the reference leak