From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E30CA5921F7 for ; Fri, 11 Sep 2026 20:03:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157016; cv=none; b=XXPTgeofGc/3UDH7WcOdcjx9SkeAbINZejMdGjcKKGiTIXnuqNySO04LmBJD2mdaK/yEdZfbdjavuj5IXLYjifw/jFhtbJ2Vdo6Ie6tw5xIOlcnUBsqGhRgf9bFIMbhhlTtTzFSRg14D0ESb5ISX2Jjs/MRmk4yDaDbR3qTRr0I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789157016; c=relaxed/simple; bh=KoRMZ3YOj/hC1tVO3K7brNeSPaQANyREvqdnIrnlSFk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=LfE4A7RNiXwVjLGL1mD8CD0k6dJwX+VwRjJpPvxAg4d8E2OtdQ6voAQWgjGsDw76wWEmT+QOjppwcHAP+ZITAuFqcc4HcyCngJ7iBuhJmjoMtjmSiikymjkOWj6hMqB7yXWoNBEGm5etWCYYj4H0KxxivfTSvAfDGTg0RJAFq1s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=nOb09v7A; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="nOb09v7A" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 719121F000FF; Fri, 11 Sep 2026 20:03:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156995; bh=nT8QdG8zaByRZxWMGBSeiNTSt6W0dLZSzRJeeh8hPf4=; h=From:To:Cc:Subject:Date:Reply-To; b=nOb09v7A5F8u4wr3bnOcuGLxT42sgQnbIR6ydO/NtIPPd63e6B8oLqGPBML5GEn5Z LMlJyvL1vydOMNAEIJbeyOQ0W6QvIEkxC+6S3t5uqIAo4bmGrIx5VbFc5uApUgiWk6 VBBiFpr9dfVJtpP+q4uXCp/DSit75mYeuTaMzVAE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89667: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache Date: Fri, 11 Sep 2026 21:45:56 +0200 Message-ID: <2026091148-CVE-2026-89667-b403@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3413; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=fsHqZD3S9qDB6OWtynQ6+byGM2h2zux6LNgImQYufpM=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLImu0U0pPcLw/72eoZ8PAbGjOav2/gOcZp0SPPt/P7 kNp6R0dsSwMgkwMsmKKLF+28RzdX3FI0cvQ9jTMHFYmkCEMXJwCMJEXOxlmMf3gbJc9YLit6Jte 9I3iAnf583bGDHOlaq64dX3Zt3Vt2c0t8z8khFxq+bYJAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then call nfsd_file_dispose_list_delayed() to move it to the per-net dispose list. If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk misses the already-unhashed file, and its drain of the per-net dispose list can run before the file has been queued. The file then sits on the per-net list with no thread to drain it, leaking both the file and its associated state. The GC worker and shrinker already hold nfsd_gc_lock while walking the LRU, but in the original code they release it before calling nfsd_file_dispose_list_delayed(). The fsnotify/lease path (nfsd_file_close_inode) has no synchronization at all. Fix this by: 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan() to cover the nfsd_file_dispose_list_delayed() call. 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three callers of nfsd_file_dispose_list_delayed() hold the lock. 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in nfsd_file_cache_shutdown_net() after the purge, so that any in-progress disposal has fully completed before the per-net list is drained. All operations inside the lock are non-sleeping (rhashtable lookups, atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is appropriate. The Linux kernel CVE team has assigned CVE-2026-89667 to this issue. Affected and fixed versions =========================== Issue introduced in 6.9 with commit ffb402596147ac583f3464ff5c48feb9423e3838 and fixed in 6.18.51 with commit 6d6b9f6a75c3767250e9c23ace4e384ab8f7843e Issue introduced in 6.9 with commit ffb402596147ac583f3464ff5c48feb9423e3838 and fixed in 7.2.4 with commit 08af9593e2b472fd98c00faf1bf03bdbb7203477 Issue introduced in 6.9 with commit ffb402596147ac583f3464ff5c48feb9423e3838 and fixed in 7.3-rc1 with commit 40162cfea79b9510380decfdd1795b754dc9f972 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89667 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/nfsd/filecache.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6d6b9f6a75c3767250e9c23ace4e384ab8f7843e https://git.kernel.org/stable/c/08af9593e2b472fd98c00faf1bf03bdbb7203477 https://git.kernel.org/stable/c/40162cfea79b9510380decfdd1795b754dc9f972