PT-2026-96333 · Azure Linux · Kernel

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: initialize copy-notify stateid before publishing it
nfsd4 copy notify() finished initializing the cpntf state after nfs4 alloc init cpntf state() had already linked it into the s2s cp stateids IDR and the parent's sc cp list, with cs count == 1 (the membership reference) and none held for the caller. A racing OFFLOAD CANCEL (crafted cl id == nn->s2s cp cl id plus the guessable so id) could reach manage cpntf state() and free the entry, turning the caller's subsequent cpn cnr stateid read and cp p stateid/cp p clid writes into use-after-free. The owning clientid was also only recorded after publication, so it could not gate an ownership check in that window.
Record cp p stateid and cp p clid inside nfs4 alloc init cpntf state() before nfs4 init cp state() publishes the entry, and return it with an extra reference. The caller reads the stateid under that reference and drops it with nfs4 put cpntf state(); on a late error the laundromat reaps the entry.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-100076

Produtos afetados

Kernel