Database/Kernel, userspace & hypervisor
Linux kernel SUNRPC: sysfs read of an RPC transport can oops when the socket is torn down concurrently
Impact
Reading the RPC transport attributes under sysfs does not hold ->recv_mutex, so ->sock can be set to NULL underneath the reader and the kernel dereferences it. The result is a host oops. An earlier fix (commit 17f09d3f619a) only narrowed the race window rather than closing it, which is why a second fix was needed. This is relevant to GPU fleets because NFS over SUNRPC is how most of them mount datasets, checkpoints and home directories, and the window opens exactly when a mount is reconnecting - the moment monitoring is most likely to be polling those sysfs files. The cost is availability only: no data disclosure, and the crash takes down the node and whatever jobs are pinned to its GPUs.
Who can reach it
Local, authenticated: a process on the host able to read the SUNRPC xprt files under sysfs, raced against RPC socket teardown. There is no remote path, and the timing dependence is reflected in the high attack-complexity rating. Containers do not see host sysfs by default.
What to do
Install a kernel carrying the fix that takes ->recv_mutex around the sysfs read; four stable branch commits are in the record. This is a kernel update and a reboot per node, schedulable as routine maintenance. In the meantime, keeping host sysfs out of reach of unprivileged workloads and not scraping the SUNRPC sysfs attributes on a tight loop both shrink the exposure.
References
Related entries
- Linux kernel (drivers/pci): Pci_device_is_present() read the Vendor/Device ID directly, which always reads as all-onesCVE-2022-50636 · Linux kernel (drivers/pci)Medium
- shadow-utils: Possible password leak during passwd(1) change (uninitialised memory)CVE-2023-4641 · shadow-utilsMedium
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeCVE-2023-52746 · Linux kernel (net/xfrm)Medium
- Intel CPU (Native BHI): Native Branch History Injection - unprivileged user leaks kernel memory despite eIBRSCVE-2024-2201 · Intel CPU (Native BHI)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.