CRITICAL Introduced in 6.19
sunrpc Backchannel UAF
CVE-2026-89546
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: close backchannel before destroying callback service A backchannel receive can complete a request while the NFS callback service is being torn down. xprt_complete_bc_request() removes the request from bc_pa_list, drops bc_alloc_count, marks the request in use, and then asks xprt_enqueue_bc_request() to hand it to the callback service. If teardown has already cleared xprt->bc_serv, xprt_enqueue_bc_request() currently returns without enqueueing or freeing the committed request. The xprt_get() taken on entry is leaked as well. If the producer wins the race before bc_serv is cleared, it can also enqueue onto sv_cb_list after nfs_callback_down() has stopped the callback threads, leaving the request linked to a svc_serv that is about to be freed. Close the producer side before callback threads are stopped. Add xprt_svc_shutdown_bc() to clear xprt->bc_serv under bc_pa_lock, and call it on callback shutdown and callback-start failure before stopping the service threads. Requests that lose the NULL transition in xprt_enqueue_bc_request() are released through the normal backchannel free path after balancing bc_slot_count. Finally, drain any remaining sv_cb_list requests after the callback threads have stopped and before svc_destroy() frees the service.
02KernelScan AI Analysis
Risk summary
A race condition in the NFS/SUNRPC backchannel request handling can leave a request linked to a callback service that is being torn down, resulting in use-after-free of the svc_serv structure. An attacker who can trigger NFSv4.1 callback teardown timing could exploit this to corrupt kernel memory. The bug requires NFS client or server functionality with backchannel support and local access to trigger the race.
Vulnerability analysis
A race condition exists in the SUNRPC backchannel request handling where a backchannel receive can complete a request while the NFS callback service is being torn down. If the producer wins the race before the callback service pointer is cleared, it can enqueue a request onto a service that is about to be freed, leaving the request linked to freed memory. The fix closes the producer side before stopping callback threads by clearing the backchannel server pointer under the proper lock, drains any remaining queued requests after threads stop, and properly frees requests that lose the NULL transition. This vulnerability is reachable from local processes that can trigger NFS callback service teardown, requiring NFS functionality to be enabled.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 6.19 | 7.3-rc1 | 3674f780f47d |
| 7.2 | 6.19 | 7.2.4 | 6debde9e3e6a |