<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:08:34 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-50121 — nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-50121</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net&lt;/p&gt;
&lt;p&gt;In the normal case, when we excute `echo 0 &amp;gt; /proc/fs/nfsd/threads`, the
function `nfs4_state_destroy_net` in `nfs4_state_shutdown_net` will
release all resources related to the hashed `nfs4_client`. If the
`nfsd_client_shrinker` is running concurrently, the `expire_client`
function will first unhash this client and then destroy it. This can
lead to the following warning. Additionally, numerous use-after-free
errors may occur as well.&lt;/p&gt;
&lt;p&gt;nfsd_client_shrinker         echo 0 &amp;gt; /proc/fs/nfsd/threads&lt;/p&gt;
&lt;p&gt;expire_client                nfsd_shutdown_net
  unhash_client                ...
                               nfs4_state_shutdown_net
                                 /* won&amp;#39;t wait shrinker exit */
  /*                             cancel_work(&amp;amp;nn-&amp;gt;nfsd_shrinker_work)
   * nfsd_file for this          /* won&amp;#39;t destroy unhashed client1 */
   * client1 still alive         nfs4_state_destroy_net
   */&lt;/p&gt;
&lt;p&gt;nfsd_file_cache_shutdown
                                 /* trigger warning */
                                 kmem_cache_destroy(nfsd_file_slab)
                                 kmem_cache_destroy(nfsd_file_mark_slab)
  /* release nfsd_file and mark */
  __destroy_client&lt;/p&gt;
&lt;p&gt;====================================================================
BUG nfsd_file (Not tainted): Objects remaining in nfsd_file on
__kmem_cac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net&lt;/p&gt;
&lt;p&gt;In the normal case, when we excute `echo 0 &amp;gt; /proc/fs/nfsd/threads`, the
function `nfs4_state_destroy_net` in `nfs4_state_shutdown_net` will
release all resources related to the hashed `nfs4_client`. If the
`nfsd_client_shrinker` is running concurrently, the `expire_client`
function will first unhash this client and then destroy it. This can
lead to the following warning. Additionally, numerous use-after-free
errors may occur as well.&lt;/p&gt;
&lt;p&gt;nfsd_client_shrinker         echo 0 &amp;gt; /proc/fs/nfsd/threads&lt;/p&gt;
&lt;p&gt;expire_client                nfsd_shutdown_net
  unhash_client                ...
                               nfs4_state_shutdown_net
                                 /* won&amp;#39;t wait shrinker exit */
  /*                             cancel_work(&amp;amp;nn-&amp;gt;nfsd_shrinker_work)
   * nfsd_file for this          /* won&amp;#39;t destroy unhashed client1 */
   * client1 still alive         nfs4_state_destroy_net
   */&lt;/p&gt;
&lt;p&gt;nfsd_file_cache_shutdown
                                 /* trigger warning */
                                 kmem_cache_destroy(nfsd_file_slab)
                                 kmem_cache_destroy(nfsd_file_mark_slab)
  /* release nfsd_file and mark */
  __destroy_client&lt;/p&gt;
&lt;p&gt;====================================================================
BUG nfsd_file (Not tainted): Objects remaining in nfsd_file on
__kmem_cac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-50121</guid>
    </item>
  </channel>
</rss>
