CVE-2024-26958

Source
https://cve.org/CVERecord?id=CVE-2024-26958
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26958.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-26958
Downstream
Related
Published
2024-05-01T05:19:04.069Z
Modified
2026-03-23T05:10:45.303964Z
Summary
nfs: fix UAF in direct writes
Details

In the Linux kernel, the following vulnerability has been resolved:

nfs: fix UAF in direct writes

In production we have been hitting the following warning consistently

------------[ cut here ]------------ refcountt: underflow; use-after-free. WARNING: CPU: 17 PID: 1800359 at lib/refcount.c:28 refcountwarnsaturate+0x9c/0xe0 Workqueue: nfsiod nfsdirectwriteschedulework [nfs] RIP: 0010:refcountwarn_saturate+0x9c/0xe0 PKRU: 55555554 Call Trace: <TASK> ? __warn+0x9f/0x130 ? refcountwarnsaturate+0x9c/0xe0 ? reportbug+0xcc/0x150 ? handlebug+0x3d/0x70 ? excinvalidop+0x16/0x40 ? asmexcinvalidop+0x16/0x20 ? refcountwarnsaturate+0x9c/0xe0 nfsdirectwriteschedulework+0x237/0x250 [nfs] processonework+0x12f/0x4a0 workerthread+0x14e/0x3b0 ? ZSTDgetCParamsinternal+0x220/0x220 kthread+0xdc/0x120 ? __btfnamevalid+0xa0/0xa0 retfromfork+0x1f/0x30

This is because we're completing the nfsdirectrequest twice in a row.

The source of this is when we have our commit requests to submit, we process them and send them off, and then in the completion path for the commit requests we have

if (nfscommitend(cinfo.mds)) nfsdirectwrite_complete(dreq);

However since we're submitting asynchronous requests we sometimes have one that completes before we submit the next one, so we end up calling complete on the nfsdirectrequest twice.

The only other place we use nfsgenericcommit_list() is in __nfscommitinode, which wraps this call in a

nfscommitbegin(); nfscommitend();

Which is a common pattern for this style of completion handling, one that is also repeated in the direct code with getdreq()/putdreq() calls around where we process events as well as in the completion paths.

Fix this by using the same pattern for the commit requests.

Before with my 200 node rocksdb stress running this warning would pop every 10ish minutes. With my patch the stress test has been running for several hours without popping.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26958.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
af7cf057933f01dc7f33ddfb5e436ad598ed17ad
Fixed
6cd3f13aaa62970b5169d990e936b2e96943bc6a
Fixed
4595d90b5d2ea5fa4d318d13f59055aa4bf3e7f5
Fixed
80d24b308b7ee7037fc90d8ac99f6f78df0a256f
Fixed
3abc2d160ed8213948b147295d77d44a22c88fa3
Fixed
e25447c35f8745337ea8bc0c9697fcac14df8605
Fixed
1daf52b5ffb24870fbeda20b4967526d8f9e12ab
Fixed
cf54f66e1dd78990ec6b32177bca7e6ea2144a95
Fixed
17f46b803d4f23c66cacce81db35fef3adb8f2af

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26958.json"