Back

MEDIUM

lockd: fix NULL dereference on lockowner allocation failure

Published Sep 11, 2026

Description

nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private().

That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed.

Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 11, 2026
Reserved Sep 11, 2026
NVD
Status Received
Modified Sep 11, 2026
Red Hat
Severity Low
Public date Sep 11, 2026