Executive brief
The Linux kernel's NFSv4 parallel NFS (pnfs) implementation uses a cache to manage data server connections. A flaw in the cache key function caused systems serving both NFSv3 and NFSv4 on the same address to incorrectly share a single cached connection, leading to mismatched protocol handling and a crash (null pointer dereference). Systems relying on pnfs flexfiles layout with multi-version support experience service interruptions or system instability.
Technical details
The vulnerability is a null pointer dereference in NFSv4 pnfs data server cache management. The root cause: nfs4_pnfs_ds_add() keys the per-network-namespace data server cache only on the multipath address set, ignoring the NFS protocol version. When two device IDs on the same address specify different NFS versions (e.g., NFSv3 and NFSv4), they incorrectly share a single nfs4_pnfs_ds cache entry and RPC client. Whichever version connects first pins the client to its protocol version; the second device is handed that mismatched client and selects incompatible rpc_call_ops, causing misaligned sequence-slot handling to dereference NULL. The fix adds the major NFS version to the cache key, allowing each version to maintain its own connection while keeping v4.0 and v4.1 sharing a client. The patch modifies the nfs4_pnfs_ds_add() function signature to accept a version parameter and updates the nfs4_pnfs_ds structure to include ds_version. No authentication or network access restrictions prevent this—any NFSv4/pnfs client mounting flexfiles layout with multi-version server support is vulnerable. Patches are available in the Linux kernel stable tree.
Affected products
- Linux Linux kernel kernel versions with pnfs flexfiles support (approximately 3.x through 6.x and later)
Timeline
- 2026-09-17: disclosed
- 2026-08-16: patched