PT-2026-90405 · Linux · Linux

CVE-2026-89689

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: don't free session slots that are still in use
nfsd4 sequence() can free the very slot it is currently processing. When the session shrinker has reduced se target maxslots below se fchannel.maxreqs, the shrink path checks three conditions before calling free session slots():
  1. se target maxslots < maxreqs (shrink was advertised)
  2. slot->sl generation == se slot gen (slot is up-to-date)
  3. seq->maxslots <= se target maxslots (client acknowledges)
However, seq->slotid is never checked against se target maxslots. A client using a slot in the range [se target maxslots, maxreqs) can satisfy all three conditions: its slot has the current generation (set by a prior SEQUENCE), and it sends sa highest slotid <= se target maxslots to acknowledge the reduction.
free session slots() then kfrees every slot at index >= se target maxslots, including the caller's own slot. The function continues to write sl seqid, sl flags, sl generation, and stores the dangling pointer in cstate->slot. Later, nfsd4 store cache entry() copies up to maxresp cached bytes of the compound reply into the freed sl data[] array, corrupting whatever slab object now occupies that address.
Additionally, a concurrent thread processing SEQUENCE on a different high-numbered slot can have its slot freed out from under it. NFSD4 SLOT INUSE is set under nn->client lock before the lock is released, so any concurrent thread past SEQUENCE will have its slot marked. However, free session slots() does not check NFSD4 SLOT INUSE before freeing.
Fix both problems by:
  1. Checking that the current request's slotid is below the shrink boundary.
  2. Scanning slots in the to-be-freed range for NFSD4 SLOT INUSE and deferring the shrink if any are active.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89689

Produtos afetados

Linux