PT-2026-96542 · Azure Linux · Kernel
Publicado
2026-09-11
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix stale s2s cp stateids IDR entry for async COPY
For an async COPY, nfsd4 copy() called nfs4 init copy state() before
dup copy fields(), so the s2s cp stateids IDR was pointed at
&u->copy->cp stateid -- memory in the per-rqstp COMPOUND buffer that is
reused by the next request. dup copy fields() copies only the value into
async copy, so the IDR slot dangled at the transient buffer for the whole
background copy. Any IDR walker then dereferences reused request memory:
the laundromat reads cs type from it and, if the bytes look like an
expired NFS4 COPYNOTIFY STID, follows into
refcount dec()/idr remove()/kfree() on garbage; manage cpntf state() has
the same exposure via idr find().
Duplicate the fields first, then register the stateid on the stable
async copy. result->cb stateid is unchanged.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel