GPU VulnDB

Database/Control plane, storage & DevOps

Linux kernel nfsd: NFSEXP_PNFS not checked when exports are configured over netlink

UnscoredCVE-2026-98250Control plane, storage & DevOpscurated

Impact

When the block-layout checks in nfsd were reworked, the NFSEXP_PNFS test moved out of nfsd4_setup_layout_type() into its callers, and the new netlink call site was not updated. The result is that the pNFS export flag is not honoured on exports configured through the netlink interface, so the layout type an export offers does not match what the administrator asked for. For an NFS server fronting shared storage for a GPU fleet, pNFS block layouts hand clients direct access to the backing device, so an export flag that is not enforced is a storage access-control question rather than a cosmetic one. The record is a one-paragraph stable-tree fix: it does not state which direction the mishandling goes, does not carry a CVSS score, and does not claim demonstrated unauthorised access. Servers that configure exports only through exportfs and /etc/exports are not on the affected codepath.

Who can reach it

Reachable by NFS clients of an affected export - anyone on the storage network who can mount it - but only on servers whose exports are configured through nfsd's netlink interface. No authentication beyond whatever the export itself requires.

What to do

Take the stable kernel update that restores the NFSEXP_PNFS check in the netlink path on your NFS servers, then restart nfsd or reboot the server; a kernel update to nfsd in practice means draining NFS clients or scheduling a server reboot. Until then, confirm which exports advertise block layouts and whether your tooling uses the netlink export path at all. The record names only the two stable commits, not a fixed release version.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.