In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix nfsd_file reference leak in nfsd4_add_rdaccess_to_wrdeleg()
nfsd4_add_rdaccess_to_wrdeleg() unconditionally overwrites fp->fi_fds[O_RDONLY] with a newly acquired nfsd_file. However, if the client already has a SHARE_ACCESS_READ open from a previous OPEN operation, this action overwrites the existing pointer without releasing its reference, orphaning the previous reference.
Additionally, the function originally stored the same nfsd_file pointer in both fp->fi_fds[O_RDONLY] and fp->fi_rdeleg_file with only a single reference. When put_deleg_file() runs, it clears fi_rdeleg_file and calls nfs4_file_put_access() to release the file.
However, nfs4_file_put_access() only releases fi_fds[O_RDONLY] when the fi_access[O_RDONLY] counter drops to zero. If another READ open exists on the file, the counter remains elevated and the nfsd_file reference from the delegation is never released. This potentially causes open conflicts on that file.
Then, on server shutdown, these leaks cause __nfsd_file_cache_purge() to encounter files with an elevated reference count that cannot be cleaned up, ultimately triggering a BUG() in kmem_cache_destroy() because there are still nfsd_file objects allocated in that cache.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 13, 2026 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1017-raspiUpgrade linux-image-aws-64kUpgrade linux-image-realtimeUpgrade linux-image-nvidia-64k-6.17Upgrade linux-image-nvidia-6.17Upgrade linux-image-nvidia-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-nvidia-64k-hwe-24.04Upgrade linux-image-gcp-64kUpgrade linux-image-gcp-6.17Upgrade linux-image-6.17.0-1013-realtimeUpgrade linux-image-virtualUpgrade linux-image-virtual-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1017-aws-64kUpgrade linux-image-oem-24.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.17.0-1015-awsUpgrade linux-image-6.17.0-1026-nvidiaUpgrade linux-image-aws-6.17Upgrade linux-image-genericUpgrade linux-image-6.17.0-1018-gcpUpgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-29-genericUpgrade linux-image-oem-24.04aUpgrade linux-image-6.17.0-1018-gcp-64kUpgrade linux-image-6.17.0-1023-oemUpgrade linux-image-oem-24.04cUpgrade linux-image-generic-64k-6.17Upgrade linux-image-6.17.0-1015-azureUpgrade linux-image-6.17.0-1014-oracle-64kUpgrade linux-image-oem-6.17Upgrade linux-image-azure-6.17Upgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-29-generic-64kUpgrade linux-image-6.17.0-1026-nvidia-64kUpgrade linux-image-generic-64kUpgrade linux-image-realtime-hwe-24.04-edgeUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-realtime-6.17Upgrade linux-image-raspiUpgrade linux-image-oracle-6.17Upgrade linux-image-oem-24.04bUpgrade linux-image-6.17.0-1015-aws-64kUpgrade linux-image-azureUpgrade linux-image-oracle-64kUpgrade linux-image-oem-24.04dUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-gcpUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.17.0-1017-awsUpgrade linux-image-generic-6.17Upgrade linux-image-6.17.0-1014-oracleUpgrade linux-image-oracle-64k-6.17 | May 25, 2026 | May 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub