Database/Control plane, storage & DevOps
Linux kernel NFSv4 client: a delayed FREE_STATEID can use a freed nfs_server
Impact
If a FREE_STATEID operation is delayed for any reason, the struct nfs_server it references can be cleaned up while the call is still in flight, giving a use-after-free; the fix pins the object for the duration of the call. The reporter hit this in practice, and the record does not establish anything beyond a crash. GPU nodes routinely mount NFS for datasets, checkpoints and home directories, so the blast radius is a node panic during mount teardown or server trouble, which on a collective training job means every rank restarts from the last checkpoint.
Who can reach it
No authentication story - this is a normal NFSv4 client code path. Reaching it needs a FREE_STATEID that is delayed, which in practice means a slow, wedged or hostile NFS server, concurrent with teardown of the mount. Whoever operates the NFS server is in a position to create that timing.
What to do
Update to a stable kernel carrying the refcount fix and reboot; the NFS client is in-kernel, so there is no daemon to restart. Because this shows up around mount teardown and server stalls, the practical interim is keeping NFS servers healthy and avoiding forced unmounts under load - it does not remove the race.
References
Related entries
- NVMe/TCP host: a short read is reported to userspace as a complete readCVE-2026-89480 · Linux kernel nvme-tcp host (short-read completion accounting)Unscored
- NVMe/TCP host: a malicious target can read host kernel memory by sending R2T for a READCVE-2026-89481 · Linux kernel nvme-tcp host (R2T direction check)Unscored
- NVMe/TCP host: C2HData for a WRITE_ZEROES command writes into a stale iteratorCVE-2026-89482 · Linux kernel nvme-tcp host (C2HData receive gate, WRITE_ZEROES path)Unscored
- Linux kernel nvme: discard fallback page is never zeroed, leaking kernel memory to the controllerCVE-2026-89483 · Linux kernel nvme core (DSM discard fallback page)Unscored
- Linux CephFS client: leaked inode reference on aborted writeback panics the node at umountCVE-2026-89646 · Linux kernel CephFS client (ceph_submit_write writeback abort at umount)Unscored
- Linux CephFS client: cap reclaim work busy-loops, burning CPU and contending dentry_list_lockCVE-2026-89647 · Linux kernel CephFS client (ceph_cap_reclaim_work / ceph_trim_dentries busy loop)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.