CVE-2026-89667
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache<br />
<br />
The shrinker, GC worker, and fsnotify/lease callbacks can unhash an<br />
nfsd_file from the rhashtable and then call<br />
nfsd_file_dispose_list_delayed() to move it to the per-net dispose list.<br />
If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk<br />
misses the already-unhashed file, and its drain of the per-net dispose<br />
list can run before the file has been queued. The file then sits on<br />
the per-net list with no thread to drain it, leaking both the file and<br />
its associated state.<br />
<br />
The GC worker and shrinker already hold nfsd_gc_lock while walking the<br />
LRU, but in the original code they release it before calling<br />
nfsd_file_dispose_list_delayed(). The fsnotify/lease path<br />
(nfsd_file_close_inode) has no synchronization at all.<br />
<br />
Fix this by:<br />
<br />
1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan()<br />
to cover the nfsd_file_dispose_list_delayed() call.<br />
<br />
2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three<br />
callers of nfsd_file_dispose_list_delayed() hold the lock.<br />
<br />
3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in<br />
nfsd_file_cache_shutdown_net() after the purge, so that any<br />
in-progress disposal has fully completed before the per-net list<br />
is drained.<br />
<br />
All operations inside the lock are non-sleeping (rhashtable lookups,<br />
atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is<br />
appropriate.
Impacto
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA


