nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
Published Sep 24, 2026
7.1
HIGHCVSS 3.1
EPSS 0.13%
Description
The hand-rolled seqcount-like protocol in nfsd_nl_rpc_status_get_dumpit() is missing a read memory barrier (smp_rmb) before its second counter check. The standard kernel read_seqcount_retry() includes smp_rmb() to ensure that all data reads complete before the counter is re-checked.
Without this barrier, on weakly-ordered architectures (ARM, POWER), the CPU may reorder field reads past the second counter check, making the retry logic ineffective: it could observe a consistent counter pair while reading fields that have been concurrently modified by the writer.
Add smp_rmb() before the second counter check to order the field reads ahead of it, matching the barrier semantics of the standard seqcount read-side. The begin-side smp_load_acquire() already pairs with the smp_store_release() in nfsd_dispatch(); with the smp_rmb() now ordering the field reads, the retry check no longer needs acquire semantics and reads the counter with a plain READ_ONCE(), as read_seqcount_retry() does.
[ cel: Use READ_ONCE instead of smp_load_acquire() ]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.7StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.7
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.13% (0.00125) | 1.91th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.13% (0.00125) | 1.90th | v5 (v2026.06.15) |
No CWE recorded.
References (4)
- https://git.kernel.org/stable/c/1aea0482b98ecd7d0249204665f2ad4ad517f66b
- https://git.kernel.org/stable/c/9b5f6475006cd8e3b5b99b8eb3cd74dbb1ce9df8
- https://git.kernel.org/stable/c/a71f161a857117e8e0264deb7d14fff5c98adcf5
- https://git.kernel.org/stable/c/f501f2f4ec1d2dfe39e21c98630314074a9b30b0
Change history (0)
No recorded changes yet.