mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks
       [not found] <2026040328-CVE-2026-31404-f58a@gregkh>
@ 2026-06-22 12:28 ` yangerkun
  2026-06-22 12:33   ` Greg Kroah-Hartman
  0 siblings, 1 reply; 3+ messages in thread
From: yangerkun @ 2026-06-22 12:28 UTC (permalink / raw)
  To: cve, linux-kernel, linux-cve-announce
  Cc: Greg Kroah-Hartman, Jeff Layton, yangerkun

Hi all,

This commit has been reverted since it does not fix any problem, should 
this CVE be rejected too?


commit 516403d4d85607fdef3ca41d4a56b54e5566fa9a
Author: Yang Erkun <yangerkun@huawei.com>
Date:   Wed May 13 10:42:52 2026 +0800

     Revert "NFSD: Defer sub-object cleanup in export put callbacks"

     This reverts commit 48db892356d6cb80f6942885545de4a6dd8d2a29.

Thanks,
Erkun.


在 2026/4/3 23:19, Greg Kroah-Hartman 写道:
> From: Greg Kroah-Hartman <gregkh@kernel.org>
> 
> Description
> ===========
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> NFSD: Defer sub-object cleanup in export put callbacks
> 
> svc_export_put() calls path_put() and auth_domain_put() immediately
> when the last reference drops, before the RCU grace period. RCU
> readers in e_show() and c_show() access both ex_path (via
> seq_path/d_path) and ex_client->name (via seq_escape) without
> holding a reference. If cache_clean removes the entry and drops the
> last reference concurrently, the sub-objects are freed while still
> in use, producing a NULL pointer dereference in d_path.
> 
> Commit 2530766492ec ("nfsd: fix UAF when access ex_uuid or
> ex_stats") moved kfree of ex_uuid and ex_stats into the
> call_rcu callback, but left path_put() and auth_domain_put() running
> before the grace period because both may sleep and call_rcu
> callbacks execute in softirq context.
> 
> Replace call_rcu/kfree_rcu with queue_rcu_work(), which defers the
> callback until after the RCU grace period and executes it in process
> context where sleeping is permitted. This allows path_put() and
> auth_domain_put() to be moved into the deferred callback alongside
> the other resource releases. Apply the same fix to expkey_put(),
> which has the identical pattern with ek_path and ek_client.
> 
> A dedicated workqueue scopes the shutdown drain to only NFSD
> export release work items; flushing the shared
> system_unbound_wq would stall on unrelated work from other
> subsystems. nfsd_export_shutdown() uses rcu_barrier() followed
> by flush_workqueue() to ensure all deferred release callbacks
> complete before the export caches are destroyed.
> 
> Reviwed-by: Jeff Layton <jlayton@kernel.org>
> 
> The Linux kernel CVE team has assigned CVE-2026-31404 to this issue.
> 
> 
> Affected and fixed versions
> ===========================
> 
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 6.18.20 with commit 2829e80d29b627886d12b5ea40856d56b516e67d
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 6.19.10 with commit f5ab1bec5fa18731e0b1b1e60c9a68667ac73ea2
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 7.0-rc5 with commit 48db892356d6cb80f6942885545de4a6dd8d2a29
> 
> Please see https://www.kernel.org for a full list of currently supported
> kernel versions by the kernel community.
> 
> Unaffected versions might change over time as fixes are backported to
> older supported kernel versions.  The official CVE entry at
> 	https://cve.org/CVERecord/?id=CVE-2026-31404
> will be updated if fixes are backported, please check that for the most
> up to date information about this issue.
> 
> 
> Affected files
> ==============
> 
> The file(s) affected by this issue are:
> 	fs/nfsd/export.c
> 	fs/nfsd/export.h
> 	fs/nfsd/nfsctl.c
> 
> 
> Mitigation
> ==========
> 
> The Linux kernel CVE team recommends that you update to the latest
> stable kernel version for this, and many other bugfixes.  Individual
> changes are never tested alone, but rather are part of a larger kernel
> release.  Cherry-picking individual commits is not recommended or
> supported by the Linux kernel community at all.  If however, updating to
> the latest release is impossible, the individual changes to resolve this
> issue can be found at these commits:
> 	https://git.kernel.org/stable/c/2829e80d29b627886d12b5ea40856d56b516e67d
> 	https://git.kernel.org/stable/c/f5ab1bec5fa18731e0b1b1e60c9a68667ac73ea2
> 	https://git.kernel.org/stable/c/48db892356d6cb80f6942885545de4a6dd8d2a29
> 


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks
  2026-06-22 12:28 ` CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks yangerkun
@ 2026-06-22 12:33   ` Greg Kroah-Hartman
  2026-06-22 12:57     ` yangerkun
  0 siblings, 1 reply; 3+ messages in thread
From: Greg Kroah-Hartman @ 2026-06-22 12:33 UTC (permalink / raw)
  To: yangerkun; +Cc: cve, linux-kernel, linux-cve-announce, Jeff Layton

On Mon, Jun 22, 2026 at 08:28:51PM +0800, yangerkun wrote:
> Hi all,
> 
> This commit has been reverted since it does not fix any problem, should this
> CVE be rejected too?
> 
> 
> commit 516403d4d85607fdef3ca41d4a56b54e5566fa9a
> Author: Yang Erkun <yangerkun@huawei.com>
> Date:   Wed May 13 10:42:52 2026 +0800
> 
>     Revert "NFSD: Defer sub-object cleanup in export put callbacks"
> 
>     This reverts commit 48db892356d6cb80f6942885545de4a6dd8d2a29.

Once that commit lands in the stable trees, yes, that should happen, our
tools will pick that up.

I'll go queue that up now, thanks.

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks
  2026-06-22 12:33   ` Greg Kroah-Hartman
@ 2026-06-22 12:57     ` yangerkun
  0 siblings, 0 replies; 3+ messages in thread
From: yangerkun @ 2026-06-22 12:57 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: cve, linux-kernel, linux-cve-announce, Jeff Layton



在 2026/6/22 20:33, Greg Kroah-Hartman 写道:
> On Mon, Jun 22, 2026 at 08:28:51PM +0800, yangerkun wrote:
>> Hi all,
>>
>> This commit has been reverted since it does not fix any problem, should this
>> CVE be rejected too?
>>
>>
>> commit 516403d4d85607fdef3ca41d4a56b54e5566fa9a
>> Author: Yang Erkun <yangerkun@huawei.com>
>> Date:   Wed May 13 10:42:52 2026 +0800
>>
>>      Revert "NFSD: Defer sub-object cleanup in export put callbacks"
>>
>>      This reverts commit 48db892356d6cb80f6942885545de4a6dd8d2a29.
> 
> Once that commit lands in the stable trees, yes, that should happen, our
> tools will pick that up.
> 
> I'll go queue that up now, thanks.
> 

Got it! Thanks!

> greg k-h
> 


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-22 12:57 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <2026040328-CVE-2026-31404-f58a@gregkh>
2026-06-22 12:28 ` CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks yangerkun
2026-06-22 12:33   ` Greg Kroah-Hartman
2026-06-22 12:57     ` yangerkun

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®