All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89540: sunrpc: init gssp_lock before publishing proc entry
@ 2026-09-11 19:43 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: init gssp_lock before publishing proc entry

create_use_gss_proxy_proc_entry() publishes /proc/net/rpc/use-gss-proxy
via proc_create_data() before init_gssp_clnt() runs mutex_init() on
sn->gssp_lock.  Once the dentry is linked under proc_subdir_lock it is
immediately reachable from userspace, so a write that lands in the
window drives set_gssp_clnt() into mutex_lock() on a zero-initialized
struct mutex.

    create_use_gss_proxy_proc_entry(net)
      proc_create_data("use-gss-proxy", ...)   /* dentry live */
      init_gssp_clnt(sn)
        mutex_init(&sn->gssp_lock)             /* too late */

    write_gssp()
      set_gssp_clnt(net)
        mutex_lock(&sn->gssp_lock)             /* uninitialized */
        gssp_rpc_create(...)
        sn->gssp_clnt = clnt
        mutex_unlock(&sn->gssp_lock)

The window spans only the two statements between proc_create_data()
returning and init_gssp_clnt(), so a writer reaches it only if the
registering thread is preempted there while another task is already
opening the freshly published file.  register_pernet_subsys() runs in
preemptible context under pernet_ops_rwsem, so that preemption is
possible, and the window widens on auth_rpcgss module load, when the
proc entry is created for every live net namespace whose tasks are
already running.  A writer that wins the race locks a zero-filled
struct mutex.  On CONFIG_DEBUG_MUTEXES the missing magic value trips a
"lock used without init" splat; on a production kernel the fast path
acquires the lock via CMPXCHG(owner, 0, current).  In the latter case
a second writer that arrives before init_gssp_clnt() re-zeroes owner
can enter set_gssp_clnt() concurrently, shut down the first writer's
clnt while it is still in use, and leak the loser's clnt.

Fix by initializing sn->gssp_lock in sunrpc_init_net() so its lifetime
matches the sunrpc_net it lives in.  sn->gssp_clnt is already NULL from
the kzalloc that backs net_generic storage, so the lazy helper is no
longer needed; drop init_gssp_clnt(), its prototype, and the call from
create_use_gss_proxy_proc_entry().  sunrpc.ko is a build-time
dependency of auth_rpcgss.ko, so sunrpc_init_net() has always run on
every netns before any auth_gss pernet init can publish the proc
entry.

The Linux kernel CVE team has assigned CVE-2026-89540 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.10 with commit 030d794bf49855f5e2a9e8dfbfad34211d1eb08b and fixed in 6.12.109 with commit f15b87521168c2a92cb1931f532cba422f856f01
	Issue introduced in 3.10 with commit 030d794bf49855f5e2a9e8dfbfad34211d1eb08b and fixed in 6.18.50 with commit edeefb111d6181a4aa278f415b005efe284b9489
	Issue introduced in 3.10 with commit 030d794bf49855f5e2a9e8dfbfad34211d1eb08b and fixed in 7.2.4 with commit 3f019571928b269feebcff59926ec13294215e0e
	Issue introduced in 3.10 with commit 030d794bf49855f5e2a9e8dfbfad34211d1eb08b and fixed in 7.3-rc1 with commit 5ce1ed6159731a41fdd0b03eedbed4e147036a5a

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89540
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/sunrpc/auth_gss/gss_rpc_upcall.c
	net/sunrpc/auth_gss/gss_rpc_upcall.h
	net/sunrpc/auth_gss/svcauth_gss.c
	net/sunrpc/sunrpc_syms.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/f15b87521168c2a92cb1931f532cba422f856f01
	https://git.kernel.org/stable/c/edeefb111d6181a4aa278f415b005efe284b9489
	https://git.kernel.org/stable/c/3f019571928b269feebcff59926ec13294215e0e
	https://git.kernel.org/stable/c/5ce1ed6159731a41fdd0b03eedbed4e147036a5a

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 19:55 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89540: sunrpc: init gssp_lock before publishing proc entry Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.