В ядре Linux устранена следующая уязвимость:
NFSD: запретить использование клиента после освобождения во время очистки отозванного состояния NFSv4.0.
nfs40_clean_admin_revoked() принимает ссылку на государственный идентификатор под
clp->cl_lock, удаляет nn->client_lock и вызывает
nfsd4_drop_revoked_stid(), который разыменовывает клиента StateID
через s->sc_client->cl_lock. Ссылка на Stateid не закрепляет
клиент, поэтому демонтаж сброшенного замка может освободить клиента
в то время как nfsd4_drop_revoked_stid() все еще использует его. Эта уборка проводится из прачечной самообслуживания, поэтому периодическая уборка может
Force_expire_client(), управляемый записью в файл Clients/<id>/ctl.
Пропустите клиента, срок действия которого уже истекает, и в противном случае закрепите его с помощью
cl_rpc_users под client_lock перед снятием блокировки, соответствие
nfsd4_revoke_states().
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfs40_clean_admin_revoked() takes a stateid reference under clp->cl_lock, drops nn->client_lock, and calls nfsd4_drop_revoked_stid(), which dereferences the stateid's client through s->sc_client->cl_lock. The stateid reference does not pin the client, so a teardown racing the dropped lock can free the client while nfsd4_drop_revoked_stid() is still using it. This cleanup runs from the laundromat, so a periodic sweep can race force_expire_client() driven by a write to the clients/<id>/ctl file. Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().
Характеристики атаки
Последствия
Строка CVSS v3.1