In the Linux kernel, the following vulnerability has been resolved:
NFSD: fix use-after-free on source server when doing inter-server copy
Use-after-free occurred when the laundromat tried to free expired cpntf_state entry on the s2s_cp_stateids list after inter-server copy completed. The sc_cp_list that the expired copy state was inserted on was already freed.
When COPY completes, the Linux client normally sends LOCKU(lock_state x), FREE_STATEID(lock_state x) and CLOSE(open_state y) to the source server. The nfs4_put_stid call from nfsd4_free_stateid cleans up the copy state from the s2s_cp_stateids list before freeing the lock state's stid.
However, sometimes the CLOSE was sent before the FREE_STATEID request. When this happens, the nfsd4_close_open_stateid call from nfsd4_close frees all lock states on its st_locks list without cleaning up the copy state on the sc_cp_list list. When the time the FREE_STATEID arrives the server returns BAD_STATEID since the lock state was freed. This causes the use-after-free error to occur when the laundromat tries to free the expired cpntf_state.
This patch adds a call to nfs4_free_cpntf_statelist in nfsd4_close_open_stateid to clean up the copy state before calling free_ol_stateid_reaplist to free the lock state's stid on the reaplist.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade kernelUpgrade kernel-headersUpgrade kernel-develUpgrade kernel-tools-debuginfoUpgrade perfUpgrade kernel-livepatch-5.10.155-138.670Upgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade kernel-toolsUpgrade python-perfUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-livepatch-5.15.75-48.135Upgrade bpftool-debuginfo | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Sep 17, 2025 | Sep 17, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade bpftoolUpgrade python3-perfUpgrade kernel-toolsUpgrade kernel-abi-stablelistsUpgrade kernelUpgrade kernel-tools-libs | Feb 3, 2026 | Feb 2, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Sep 15, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotg-5.15Upgrade linux-intel-iotgUpgrade linux-lowlatencyUpgrade linux-azureUpgrade linux-kvmUpgrade linux-gkeopUpgrade linux-ibmUpgrade linux-lowlatency-hwe-5.15Upgrade linux-realtimeUpgrade linux-oracle-5.15Upgrade linux-bluefieldUpgrade linux-gcp-5.15Upgrade linux-oracleUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-riscv-5.15Upgrade linux-nvidiaUpgrade linux-azure-5.15Upgrade linux-awsUpgrade linux-gcpUpgrade linux-aws-5.15Upgrade linuxUpgrade linux-gke | Sep 19, 2025 | Sep 16, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 15, 2025 | Sep 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub