{"api_version":"1","generated_at":"2026-06-04T07:24:48+00:00","cve":"CVE-2026-46256","urls":{"html":"https://cve.report/CVE-2026-46256","api":"https://cve.report/api/cve/CVE-2026-46256.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-46256","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-46256"},"summary":{"title":"NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages\n\nLOCALIO is an NFS loopback mount optimization that avoids using the\nnetwork for READ, WRITE and COMMIT if the NFS client and server are\ndetermined to be on the same system. But because LOCALIO is still\nfundamentally \"just NFS loopback mount\" it is susceptible to recursion\ndeadlock via direct reclaim, e.g.: NFS LOCALIO down to XFS and then\nback into NFS via nfs_writepages.\n\nFix LOCALIO's potential for direct reclaim deadlock by ensuring that\nall its page cache allocations are done from GFP_NOFS context.\n\nThanks to Ben Coddington for pointing out commit ad22c7a043c2 (\"xfs:\nprevent stack overflows from page cache allocation\").","state":"PUBLISHED","assigner":"Linux","published_at":"2026-06-03 18:16:26","updated_at":"2026-06-03 18:16:26"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/67435d2d8a33a75f9647724952cb1b18279d2e95","name":"https://git.kernel.org/stable/c/67435d2d8a33a75f9647724952cb1b18279d2e95","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6a5de0c4fc0f217eea945d3d72c34ee30d72cbc9","name":"https://git.kernel.org/stable/c/6a5de0c4fc0f217eea945d3d72c34ee30d72cbc9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ae26a4cf2baf0a44c538dc093504d1994b02dade","name":"https://git.kernel.org/stable/c/ae26a4cf2baf0a44c538dc093504d1994b02dade","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-46256","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46256","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 70ba381e1a431245c137ed597ec6a05991c79bd9 ae26a4cf2baf0a44c538dc093504d1994b02dade git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 70ba381e1a431245c137ed597ec6a05991c79bd9 6a5de0c4fc0f217eea945d3d72c34ee30d72cbc9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 70ba381e1a431245c137ed597ec6a05991c79bd9 67435d2d8a33a75f9647724952cb1b18279d2e95 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.14 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.19.4 6.19.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfs/localio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"ae26a4cf2baf0a44c538dc093504d1994b02dade","status":"affected","version":"70ba381e1a431245c137ed597ec6a05991c79bd9","versionType":"git"},{"lessThan":"6a5de0c4fc0f217eea945d3d72c34ee30d72cbc9","status":"affected","version":"70ba381e1a431245c137ed597ec6a05991c79bd9","versionType":"git"},{"lessThan":"67435d2d8a33a75f9647724952cb1b18279d2e95","status":"affected","version":"70ba381e1a431245c137ed597ec6a05991c79bd9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/nfs/localio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.12"},{"lessThan":"6.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.14","versionType":"semver"},{"lessThanOrEqual":"6.19.*","status":"unaffected","version":"6.19.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.0","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.14","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.19.4","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0","versionStartIncluding":"6.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages\n\nLOCALIO is an NFS loopback mount optimization that avoids using the\nnetwork for READ, WRITE and COMMIT if the NFS client and server are\ndetermined to be on the same system. But because LOCALIO is still\nfundamentally \"just NFS loopback mount\" it is susceptible to recursion\ndeadlock via direct reclaim, e.g.: NFS LOCALIO down to XFS and then\nback into NFS via nfs_writepages.\n\nFix LOCALIO's potential for direct reclaim deadlock by ensuring that\nall its page cache allocations are done from GFP_NOFS context.\n\nThanks to Ben Coddington for pointing out commit ad22c7a043c2 (\"xfs:\nprevent stack overflows from page cache allocation\")."}],"providerMetadata":{"dateUpdated":"2026-06-03T15:49:53.168Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/ae26a4cf2baf0a44c538dc093504d1994b02dade"},{"url":"https://git.kernel.org/stable/c/6a5de0c4fc0f217eea945d3d72c34ee30d72cbc9"},{"url":"https://git.kernel.org/stable/c/67435d2d8a33a75f9647724952cb1b18279d2e95"}],"title":"NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-46256","datePublished":"2026-06-03T15:49:53.168Z","dateReserved":"2026-05-13T15:03:33.108Z","dateUpdated":"2026-06-03T15:49:53.168Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-03 18:16:26","lastModifiedDate":"2026-06-03 18:16:26","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"46256","Ordinal":"1","Title":"NFS/localio: prevent direct reclaim recursion into NFS via nfs_w","CVE":"CVE-2026-46256","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"46256","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages\n\nLOCALIO is an NFS loopback mount optimization that avoids using the\nnetwork for READ, WRITE and COMMIT if the NFS client and server are\ndetermined to be on the same system. But because LOCALIO is still\nfundamentally \"just NFS loopback mount\" it is susceptible to recursion\ndeadlock via direct reclaim, e.g.: NFS LOCALIO down to XFS and then\nback into NFS via nfs_writepages.\n\nFix LOCALIO's potential for direct reclaim deadlock by ensuring that\nall its page cache allocations are done from GFP_NOFS context.\n\nThanks to Ben Coddington for pointing out commit ad22c7a043c2 (\"xfs:\nprevent stack overflows from page cache allocation\").","Type":"Description","Title":"NFS/localio: prevent direct reclaim recursion into NFS via nfs_w"}]}}}