Database/Kernel, userspace & hypervisor
Linux kernel nfsd: unserialized grace_ended flag lets two contexts double-free every client reclaim record
Impact
nfsd4_end_grace() guarded its drain path with a plain boolean read followed by a write, with nothing serializing the two. The laundromat worker and a RECLAIM_COMPLETE compound can both observe the flag clear, both set it, and both enter nfs4_release_reclaim(), which walks reclaim_str_hashtbl unlocked and list_del + kfree's every entry - list corruption and a double free of every nfs4_client_reclaim, with a concurrent lookup reading freed memory. The window is server restart plus reclaim, so it is reachable by NFS clients reconnecting after the server comes back. On a GPU cluster this matters where nodes export or re-export NFS for datasets and checkpoints: the failure mode is a kernel crash on the file server, which stalls every job holding that mount. The fix converts the flags to an unsigned long word and uses test_and_set_bit().
Who can reach it
Remote NFS clients performing reclaim against an in-kernel nfsd server during the grace period after a restart. No authentication beyond what the export already requires; it is a race, so it is not reliably triggerable on demand.
What to do
Update to a stable kernel with the linked commits and reboot the NFS servers - a reboot per file server, which means an outage window for every client holding those mounts. No runtime mitigation; the race only opens around nfsd grace-period end, so minimizing nfsd restarts reduces exposure without removing it.
References
Related entries
- Linux kernel net/rds: teardown samples RDS_IN_XMIT instead of owning it, racing the transmit path into freed ring stateCVE-2026-98069 · Linux kernel net/rds (connection teardown vs transmit/refill fastpath locking)High
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- util-linux nsenter: --join-cgroup leaks a root-opened cgroup.procs fd into the target containerCVE-2026-78408 · util-linux nsenter (--join-cgroup descriptor leak across execve)High
- Linux kernel KVM/arm64: guest-controlled TLBI Range can overflow the hypervisor's range computationCVE-2026-89911 · Linux kernel KVM arm64 (TLBI by Range)High
- Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_user: Straight local-to-root. RDS - theCVE-2010-3904 · Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_userHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.