Re: [PATCH] nfsd: hold cl_lock in client_has_state()

From: Greg Kroah-Hartman

Date: Sat Aug 29 2026 - 01:54:31 EST


On Fri, Aug 28, 2026 at 09:45:33AM -0400, Chuck Lever wrote:
>
>
> On Fri, Aug 28, 2026, at 1:29 AM, Greg KH wrote:
> > On Fri, Aug 28, 2026 at 12:19:25AM -0400, Cen Zhang (Microsoft Security
> > FORGE Labs) wrote:
> >> client_has_openowners() walks clp->cl_openowners and reads so_stateids
> >> without clp->cl_lock. nfs4_put_stateowner() unhashes that openowner under
> >> cl_lock and then frees it, so a concurrent EXCHANGE_ID with mismatched
> >> creds can use-after-free the nfs4_openowner.
> >>
> >> BUG: KASAN: slab-use-after-free in client_has_state+0x10a/0x140
> >> fs/nfsd/nfs4state.c:3718 client_has_openowners()
> >> nfsd4_exchange_id
> >> nfsd4_proc_compound
> >> nfsd_dispatch
> >> svc_process
> >>
> >> Take clp->cl_lock while client_has_state() walks the openowner list.
> >>
> >> Fixes: 4eaea1342507 ("nfsd: improve client_has_state to check for unused openowners")
> >> Reported-by: Xiang Mei (Microsoft) <xmei5@xxxxxxx>
> >> Cc: AutonomousCodeSecurity@xxxxxxxxxxxxx
> >> Cc: stable@xxxxxxxxxxxxxxx
> >> Signed-off-by: Cen Zhang (Microsoft Security FORGE Labs) <blbllhy@xxxxxxxxx>
> >
> > Please use your microsoft.com email address, and not a random gmail.com
> > address. It's kind of odd that Microsoft would have to rely on Google
> > to send kernel patches :)
>
> Greg, would you prefer that I hold off on applying this to nfsd-testing
> until Cen can post this one again?

That's your call.