PT-2026-104977 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
nfsd: convert nfsd net boolean flags to unsigned long flags word
nfsd net contains several boolean fields that are accessed from concurrent contexts without serialization. In particular, nfsd4 end grace() guards its drain path with a plain bool:
if (nn->grace ended) return; nn->grace ended = true;
The read and the write are independent, and nothing in struct nfsd net serializes them. At least two contexts can reach this code with no lock held:
laundromat path laundry wq kworker nfs4 laundromat() nfsd4 end grace()
RECLAIM COMPLETE path nfsd compound kthread nfsd4 reclaim complete() inc reclaim complete() nfsd4 end grace()
Both callers can observe grace ended == false on different CPUs, both store true, and both proceed into nfsd4 record grace done(), which invokes the active client tracking ops->grace done callback. For tracking ops that drain reclaim str hashtbl (legacy tracking ops via nfsd4 recdir purge old, and the cld v1+ ops via nfsd4 cld grace done), grace done calls nfs4 release reclaim(), which walks every bucket of reclaim str hashtbl with no lock and calls nfs4 remove reclaim record() (list del + kfree) on each entry. Two concurrent walkers corrupt the list and double-free every nfs4 client reclaim. A concurrent nfsd4 find reclaim client() iterating the same bucket reads through freed memory.
A third call site exists in nfs4 state start net() on the skip grace startup path, but it runs under nfsd mutex before any client has connected and before the laundromat's first delayed work fires, so it cannot race with the two callers above.
Replace the scattered boolean fields in nfsd net with a single unsigned long flags word and an enum nfsd net flag for the bit positions. The grace ended race is fixed by using test and set bit(), which is atomic on all architectures. The remaining flags (grace end forced, in grace, somebody reclaimed, track reclaim completes, nfsd net up, lockd up) are converted to use test bit/set bit/clear bit for consistency. This avoids sub-word cmpxchg issues on architectures like Hexagon that only support word-sized atomic operations.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103946

Affected Products

Kernel