[PATCH 0/3] Fix NFSD post-shutdown use-after-free in the unlock_filesystem paths

Chuck Lever <[email protected]>
Newsgroups gmane.linux.nfs
Message-ID <[email protected]>
Musaab Khan reported that a local administrator holding CAP_SYS_ADMIN
can trigger a use-after-free in nfsd by writing a filesystem path to
/proc/fs/nfsd/unlock_filesystem after the server has been stopped.

write_unlock_fs() calls nfsd4_cancel_copy_by_sb() before it takes
nfsd_mutex and before it confirms that nn->nfsd_serv is set. Once nfsd
has shut down, nfs4_state_destroy_net() has freed nn->conf_id_hashtbl
but left the pointer intact, so the cancel helper walks freed slab
memory as an array of struct list_head and then dereferences a
bogus nfs4_client when it takes clp->async_lock. KASAN reports a
slab-use-after-free read in nfsd4_cancel_copy_by_sb().

nfsd4_revoke_states() walks the same state tables and for that reason
already runs only under nfsd_mutex with nn->nfsd_serv confirmed
present. The async COPY cancel was added ahead of that protected
section, so it escaped the guard. The first two patches move the cancel
inside the protected section on both the procfs unlock_filesystem path
and the NFSD_CMD_UNLOCK_FILESYSTEM netlink path. Async copies exist
only while the server runs, so gating the cancel on nn->nfsd_serv loses
nothing.

The netlink command that patch 2 corrects, 327c5168eff2 ("NFSD: Add
NFSD_CMD_UNLOCK_FILESYSTEM netlink command"), has not yet reached
mainline; it sits in nfsd-next, destined for v7.2. Patch 2 therefore
applies to nfsd-next, not to a released kernel, and needs no stable
backport.

The last patch adds lockdep_assert_held(&nfsd_mutex) to the state-table
walkers and documents the nfsd_mutex / nn->nfsd_serv precondition in
a Context: kdoc section, so a future caller added to this path cannot
silently reintroduce the same use-after-free.

---
Chuck Lever (3):
      NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
      NFSD: Prevent post-shutdown use-after-free in NFSD_CMD_UNLOCK_FILESYSTEM
      NFSD: Annotate caller preconditions for the state-table walkers

 fs/nfsd/nfs4proc.c  |  6 ++++++
 fs/nfsd/nfs4state.c | 16 +++++++++++++++-
 fs/nfsd/nfsctl.c    | 14 ++++++++------
 3 files changed, 29 insertions(+), 7 deletions(-)
---
base-commit: 56d6b74e37708005739ef00bb59db34bffac15a8
change-id: 20260613-unlock-filesystem-uaf-99a7577caea2

Best regards,
--  
Chuck Lever
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.