lockd: pin next file across nlm_inspect_file lock-drop
Summary
| CVE | CVE-2026-89485 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:30 UTC |
| Updated | 2026-09-11 20:19:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
lockd: pin next file across nlm_inspect_file lock-drop
nlm_traverse_files() pins the current file with f_count++ across
a mutex_unlock for nlm_inspect_file(), but nothing pins the saved
next pointer. A concurrent nlm_release_file() can kfree the next
file during the unlock window, and the iterator dereferences freed
memory on the next loop step.
Pin both current and next before the lock-drop. Advance by
swapping the pinned cursors at the end of each iteration so next
is always held alive across the unlock.
Always call nlm_file_release() after dropping the iteration pin,
regardless of whether the file matched the predicate. Use
nlm_file_inuse(), which does a live walk of the inode lock list,
rather than the cached f_locks field, so skipped files that never
ran nlm_inspect_file() are evaluated correctly.
Because every file in a hash bucket is now pinned and released,
files skipped by the is_failover_file predicate that have no
locks, blocks, shares, or external references are deleted during
traversal. The old code never evaluated skipped files for
cleanup. The new behavior is intentional: such files are stale
and should not persist in the table. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 c24bdb7df2f34bdc38ca8a73796f5acb40f1830c git |
Not specified |
| CNA |
Linux |
Linux |
affected 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 41f0a6d31615fcae261bf28a0aa50050dc93a401 git |
Not specified |
| CNA |
Linux |
Linux |
affected 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 e999a88133654c6dfc68487fb49da5f20dfa2d4f git |
Not specified |
| CNA |
Linux |
Linux |
affected 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 526c49cff3f72c3ec74752016380c7567040581b git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/526c49cff3f72c3ec74752016380c7567040581b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e999a88133654c6dfc68487fb49da5f20dfa2d4f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c24bdb7df2f34bdc38ca8a73796f5acb40f1830c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/41f0a6d31615fcae261bf28a0aa50050dc93a401 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.