CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's NFS server, specifically in the handling of revoked layout state IDs (stid) during the state ID drop process. If an admin revokes a layout stid, the system may fail to properly release and unhash it, potentially leading to resource leaks and denial of service as the stid remains in memory until the client is destroyed. Organizations utilizing NFS services on Linux should prioritize addressing this issue to prevent potential resource exhaustion and ensure system stability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() nfsd4_drop_revoked_stid() has no SC_TYPE_LAYOUT case, so when a client sends FREE_STATEID for an admin-revoked layout stid, the default branch releases cl_lock and returns without unhashing or releasing the stid. The stid remains in the IDR and on the per-client list until the client is destroyed. Remove the layout stid from the per-client list and call nfs4_put_stid() to drop the creation reference. When the refcount reaches zero, nfsd4_free_layout_stateid() handles the remaining cleanup: cancelling the fence worker, removing from the per-file list, and freeing the slab object.