Executive brief
The Linux kernel's NFSv4 client implementation contains a bug in file lease handling when NFSv4 delegations are in use. A race condition between lease setup and delegation return can pass a NULL pointer to an internal cleanup function, causing a kernel crash that impacts system availability and reliability.
Technical details
The vulnerability is a null pointer dereference in the NFSv4 client's file lease management code. When nfs4_add_lease() races with a delegation return, it calls nfs4_delete_lease() with the priv parameter, which can legitimately be NULL in certain code paths. Passing a NULL pointer to this function eventually leads to a NULL pointer dereference in generic_setlease(). The bug is triggered only when both NFSv4 delegations and application leases are in use simultaneously, and requires a race condition between lease setup and delegation return. The fix involves capturing the lease owner before the race window and passing the valid owner reference instead of the NULL priv pointer. This is a kernel-level issue with no direct network attack surface; local or system-level conditions are required to trigger the race condition.
Affected products
- Linux Linux kernel multiple versions (2.6.x through 6.x)
Timeline
- 2026-09-17: disclosed