PT-2026-97888 · Linux · Linux Kernel
CVE-2026-93221
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
In the Linux kernel, the
nfsd net structure contains boolean fields accessed from concurrent contexts without proper serialization. Specifically, the nfsd4 end grace() function uses a plain boolean to guard its drain path, allowing multiple contexts—such as the laundromat path via nfs4 laundromat() and the RECLAIM COMPLETE path via nfsd4 reclaim complete()—to simultaneously observe the flag as false and proceed into nfsd4 record grace done(). This triggers the grace done callback, which calls nfs4 release reclaim(). Because this function iterates through the reclaim str hashtbl without a lock, concurrent execution leads to list corruption and a double-free of nfs4 client reclaim entries. Additionally, a concurrent call to nfsd4 find reclaim client() may result in reading freed memory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel