nfsd: provide locking for v4_end_grace
Published Jan 23, 2026
7.8
HIGHCVSS 3.1
EPSS 0.15%
Description
Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hashtbl in particularly.
We cannot hold nfsd_mutex across the nfsd4_end_grace() call as that is held while client_tracking_op->init() is called and that can wait for an upcall to nfsdcltrack which can write to v4_end_grace, resulting in a deadlock.
nfsd4_end_grace() is also called by the landromat work queue and this doesn't require locking as server shutdown will stop the work and wait for it before freeing anything that nfsd4_end_grace() might access.
However, we must be sure that writing to v4_end_grace doesn't restart the work item after shutdown has already waited for it. For this we add a new flag protected with nn->client_lock. It is set only while it is safe to make client tracking calls, and v4_end_grace only schedules work while the flag is set with the spinlock held.
So this patch adds a nfsd_net field "client_tracking_active" which is set as described. Another field "grace_end_forced", is set when v4_end_grace is written. After this is set, and providing client_tracking_active is set, the laundromat is scheduled. This "grace_end_forced" field bypasses other checks for whether the grace period has finished.
This resolves a race which can result in use-after-free.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.18
- Version 5.10.248StatusunaffectedConstraints<=5.10.*
- Version 5.15.198StatusunaffectedConstraints<=5.15.*
- Version 6.1.161StatusunaffectedConstraints<=6.1.*
- Version 6.12.66StatusunaffectedConstraints<=6.12.*
- Version 6.18.6StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version 6.6.121StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 3.18 · < 5.10.248
- ≥ 5.11 · < 5.15.198
- ≥ 5.16 · < 6.1.161
- ≥ 6.2 · < 6.6.121
- ≥ 6.7 · < 6.12.66
- ≥ 6.13 · < 6.18.6
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A race in the NFSv4 admin “end grace” control can lead to a use-after-free when a write to v4_end_grace overlaps with server shutdown, causing freed state (e.g., reclaim tracking tables) to be accessed. The trigger is local via an administrative interface (typically requiring root-equivalent privileges), and the impact is a kernel crash.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-22980 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2432385 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4321 Advisory
- https://git.kernel.org/stable/c/06600719d0f7a723811c45e4d51f5b742f345309 Patch
- https://git.kernel.org/stable/c/2857bd59feb63fcf40fe4baf55401baea6b4feb4 Patch
- https://git.kernel.org/stable/c/34eb22836e0cdba093baac66599d68c4cd245a9d Patch
- https://git.kernel.org/stable/c/53f07d095e7e680c5e4569a55a019f2c0348cdc6 Patch
- https://git.kernel.org/stable/c/ba4811c8b433bfa681729ca42cc62b6034f223b0 Patch
- https://git.kernel.org/stable/c/ca97360860eb02e3ae4ba42c19b439a0fcecbf06 Patch
- https://git.kernel.org/stable/c/e8bfa2401d4c51eca6e48e9b33c798828ca9df61 Patch
- https://lore.kernel.org/linux-cve-announce/2026012347-CVE-2026-22980-6031@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-22980
- https://www.cve.org/CVERecord?id=CVE-2026-22980
Change history (0)
No recorded changes yet.