mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: yangerkun <yangerkun@huawei.com>
To: <cve@kernel.org>, <linux-kernel@vger.kernel.org>,
	<linux-cve-announce@vger.kernel.org>
Cc: Greg Kroah-Hartman <gregkh@kernel.org>,
	Jeff Layton <jlayton@kernel.org>,
	yangerkun <yangerkun@huawei.com>
Subject: Re: CVE-2026-31404: NFSD: Defer sub-object cleanup in export put callbacks
Date: Mon, 22 Jun 2026 20:28:51 +0800	[thread overview]
Message-ID: <fc901af4-48f2-48ee-b1dd-615f6a6d298d@huawei.com> (raw)
In-Reply-To: <2026040328-CVE-2026-31404-f58a@gregkh>

Hi all,

This commit has been reverted since it does not fix any problem, should 
this CVE be rejected too?


commit 516403d4d85607fdef3ca41d4a56b54e5566fa9a
Author: Yang Erkun <yangerkun@huawei.com>
Date:   Wed May 13 10:42:52 2026 +0800

     Revert "NFSD: Defer sub-object cleanup in export put callbacks"

     This reverts commit 48db892356d6cb80f6942885545de4a6dd8d2a29.

Thanks,
Erkun.


在 2026/4/3 23:19, Greg Kroah-Hartman 写道:
> From: Greg Kroah-Hartman <gregkh@kernel.org>
> 
> Description
> ===========
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> NFSD: Defer sub-object cleanup in export put callbacks
> 
> svc_export_put() calls path_put() and auth_domain_put() immediately
> when the last reference drops, before the RCU grace period. RCU
> readers in e_show() and c_show() access both ex_path (via
> seq_path/d_path) and ex_client->name (via seq_escape) without
> holding a reference. If cache_clean removes the entry and drops the
> last reference concurrently, the sub-objects are freed while still
> in use, producing a NULL pointer dereference in d_path.
> 
> Commit 2530766492ec ("nfsd: fix UAF when access ex_uuid or
> ex_stats") moved kfree of ex_uuid and ex_stats into the
> call_rcu callback, but left path_put() and auth_domain_put() running
> before the grace period because both may sleep and call_rcu
> callbacks execute in softirq context.
> 
> Replace call_rcu/kfree_rcu with queue_rcu_work(), which defers the
> callback until after the RCU grace period and executes it in process
> context where sleeping is permitted. This allows path_put() and
> auth_domain_put() to be moved into the deferred callback alongside
> the other resource releases. Apply the same fix to expkey_put(),
> which has the identical pattern with ek_path and ek_client.
> 
> A dedicated workqueue scopes the shutdown drain to only NFSD
> export release work items; flushing the shared
> system_unbound_wq would stall on unrelated work from other
> subsystems. nfsd_export_shutdown() uses rcu_barrier() followed
> by flush_workqueue() to ensure all deferred release callbacks
> complete before the export caches are destroyed.
> 
> Reviwed-by: Jeff Layton <jlayton@kernel.org>
> 
> The Linux kernel CVE team has assigned CVE-2026-31404 to this issue.
> 
> 
> Affected and fixed versions
> ===========================
> 
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 6.18.20 with commit 2829e80d29b627886d12b5ea40856d56b516e67d
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 6.19.10 with commit f5ab1bec5fa18731e0b1b1e60c9a68667ac73ea2
> 	Issue introduced in 6.14 with commit c224edca7af028828e2ad866b61d731b5e72b46d and fixed in 7.0-rc5 with commit 48db892356d6cb80f6942885545de4a6dd8d2a29
> 
> Please see https://www.kernel.org for a full list of currently supported
> kernel versions by the kernel community.
> 
> Unaffected versions might change over time as fixes are backported to
> older supported kernel versions.  The official CVE entry at
> 	https://cve.org/CVERecord/?id=CVE-2026-31404
> will be updated if fixes are backported, please check that for the most
> up to date information about this issue.
> 
> 
> Affected files
> ==============
> 
> The file(s) affected by this issue are:
> 	fs/nfsd/export.c
> 	fs/nfsd/export.h
> 	fs/nfsd/nfsctl.c
> 
> 
> Mitigation
> ==========
> 
> The Linux kernel CVE team recommends that you update to the latest
> stable kernel version for this, and many other bugfixes.  Individual
> changes are never tested alone, but rather are part of a larger kernel
> release.  Cherry-picking individual commits is not recommended or
> supported by the Linux kernel community at all.  If however, updating to
> the latest release is impossible, the individual changes to resolve this
> issue can be found at these commits:
> 	https://git.kernel.org/stable/c/2829e80d29b627886d12b5ea40856d56b516e67d
> 	https://git.kernel.org/stable/c/f5ab1bec5fa18731e0b1b1e60c9a68667ac73ea2
> 	https://git.kernel.org/stable/c/48db892356d6cb80f6942885545de4a6dd8d2a29
> 


       reply	other threads:[~2026-06-22 12:29 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <2026040328-CVE-2026-31404-f58a@gregkh>
2026-06-22 12:28 ` yangerkun [this message]
2026-06-22 12:33   ` Greg Kroah-Hartman
2026-06-22 12:57     ` yangerkun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=fc901af4-48f2-48ee-b1dd-615f6a6d298d@huawei.com \
    --to=yangerkun@huawei.com \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=jlayton@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®