CVE-2026-93221
In the Linux kernel, the following vulnerability has been resolved:
nfsd: convert nfsd_net boolean flags to unsigned long flags word
nfsd_net contains several boolean fields that are accessed from concurrent contexts without serialization. In particular, nfsd4_end_grace() guards its drain path with a plain bool:
The read and the write are independent, and nothing in struct nfsd_net serializes them. At least two contexts can reach this code with no lock held:
Both callers can observe grace_ended == false on different CPUs, both store true, and both proceed into nfsd4_record_grace_done(), which invokes the active client_tracking_ops->grace_done callback.
Leer descripción completaMostrar menos
For tracking ops that drain reclaim_str_hashtbl (legacy_tracking_ops via nfsd4_recdir_purge_old, and the cld v1+ ops via nfsd4_cld_grace_done), grace_done calls nfs4_release_reclaim(), which walks every bucket of reclaim_str_hashtbl with no lock and calls nfs4_remove_reclaim_record() (list_del + kfree) on each entry. Two concurrent walkers corrupt the list and double-free every nfs4_client_reclaim. A concurrent nfsd4_find_reclaim_client() iterating the same bucket reads through freed memory.
A third call site exists in nfs4_state_start_net() on the skip_grace startup path, but it runs under nfsd_mutex before any client has connected and before the laundromat's first delayed work fires, so it cannot race with the two callers above.
Replace the scattered boolean fields in nfsd_net with a single unsigned long flags word and an enum nfsd_net_flag for the bit positions. The grace_ended race is fixed by using test_and_set_bit(), which is atomic on all architectures. The remaining flags (grace_end_forced, in_grace, somebody_reclaimed, track_reclaim_completes, nfsd_net_up, lockd_up) are converted to use test_bit/set_bit/clear_bit for consistency. This avoids sub-word cmpxchg issues on architectures like Hexagon that only support word-sized atomic operations.
Detalles técnicos trazas, registros y código del informe original
if (nn->grace_ended)
return;
nn->grace_ended = true;
laundromat path
laundry_wq kworker
nfs4_laundromat()
nfsd4_end_grace()
RECLAIM_COMPLETE path
nfsd compound kthread
nfsd4_reclaim_complete()
inc_reclaim_complete()
nfsd4_end_grace()CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access45 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact55 %
Vulnerabilidad de race condition en kernel Linux (AV:N) sin autenticación requerida que causa corrupción de memoria y DoS; remotamente explotable en contextos NFS con acceso de red sin privilegios previos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93221",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "362063a595be959bc08f4163e6405a0266740091",
"lessThan": "df5922fe09a8131c793ffa86adf204999b0470f8",
"versionType": "git"
},
{
"status": "affected",
"version": "362063a595be959bc08f4163e6405a0266740091",
"lessThan": "11a5fe42e1811f793e04ef885b639ea7668f439d",
"versionType": "git"
}
],
"programFiles": [
"fs/nfsd/netns.h",
"fs/nfsd/nfs4proc.c",
"fs/nfsd/nfs4recover.c",
"fs/nfsd/nfs4state.c",
"fs/nfsd/nfsctl.c",
"fs/nfsd/nfssvc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/nfsd/netns.h",
"fs/nfsd/nfs4proc.c",
"fs/nfsd/nfs4recover.c",
"fs/nfsd/nfs4state.c",
"fs/nfsd/nfsctl.c",
"fs/nfsd/nfssvc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:17.310",
"references": [
{
"url": "https://git.kernel.org/stable/c/11a5fe42e1811f793e04ef885b639ea7668f439d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/df5922fe09a8131c793ffa86adf204999b0470f8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: convert nfsd_net boolean flags to unsigned long flags word\n\nnfsd_net contains several boolean fields that are accessed from\nconcurrent contexts without serialization. In particular,\nnfsd4_end_grace() guards its drain path with a plain bool:\n\n if (nn->grace_ended)\n return;\n nn->grace_ended = true;\n\nThe read and the write are independent, and nothing in struct\nnfsd_net serializes them. At least two contexts can reach this\ncode with no lock held:\n\n laundromat path\n laundry_wq kworker\n nfs4_laundromat()\n nfsd4_end_grace()\n\n RECLAIM_COMPLETE path\n nfsd compound kthread\n nfsd4_reclaim_complete()\n inc_reclaim_complete()\n nfsd4_end_grace()\n\nBoth callers can observe grace_ended == false on different CPUs,\nboth store true, and both proceed into nfsd4_record_grace_done(),\nwhich invokes the active client_tracking_ops->grace_done callback.\nFor tracking ops that drain reclaim_str_hashtbl (legacy_tracking_ops\nvia nfsd4_recdir_purge_old, and the cld v1+ ops via\nnfsd4_cld_grace_done), grace_done calls nfs4_release_reclaim(),\nwhich walks every bucket of reclaim_str_hashtbl with no lock and\ncalls nfs4_remove_reclaim_record() (list_del + kfree) on each\nentry. Two concurrent walkers corrupt the list and double-free\nevery nfs4_client_reclaim. A concurrent nfsd4_find_reclaim_client()\niterating the same bucket reads through freed memory.\n\nA third call site exists in nfs4_state_start_net() on the\nskip_grace startup path, but it runs under nfsd_mutex before any\nclient has connected and before the laundromat's first delayed\nwork fires, so it cannot race with the two callers above.\n\nReplace the scattered boolean fields in nfsd_net with a single\nunsigned long flags word and an enum nfsd_net_flag for the bit\npositions. The grace_ended race is fixed by using\ntest_and_set_bit(), which is atomic on all architectures. The\nremaining flags (grace_end_forced, in_grace, somebody_reclaimed,\ntrack_reclaim_completes, nfsd_net_up, lockd_up) are converted to\nuse test_bit/set_bit/clear_bit for consistency. This avoids\nsub-word cmpxchg issues on architectures like Hexagon that only\nsupport word-sized atomic operations."
}
],
"lastModified": "2026-09-25T05:17:00.150",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}