{"id":"DEBIAN-CVE-2024-50121","details":"In the Linux kernel, the following vulnerability has been resolved:  nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net  In the normal case, when we excute `echo 0 \u003e /proc/fs/nfsd/threads`, the function `nfs4_state_destroy_net` in `nfs4_state_shutdown_net` will release all resources related to the hashed `nfs4_client`. If the `nfsd_client_shrinker` is running concurrently, the `expire_client` function will first unhash this client and then destroy it. This can lead to the following warning. Additionally, numerous use-after-free errors may occur as well.  nfsd_client_shrinker         echo 0 \u003e /proc/fs/nfsd/threads  expire_client                nfsd_shutdown_net   unhash_client                ...                                nfs4_state_shutdown_net                                  /* won't wait shrinker exit */   /*                             cancel_work(&nn-\u003enfsd_shrinker_work)    * nfsd_file for this          /* won't destroy unhashed client1 */    * client1 still alive         nfs4_state_destroy_net    */                                 nfsd_file_cache_shutdown                                  /* trigger warning */                                  kmem_cache_destroy(nfsd_file_slab)                                  kmem_cache_destroy(nfsd_file_mark_slab)   /* release nfsd_file and mark */   __destroy_client  ==================================================================== BUG nfsd_file (Not tainted): Objects remaining in nfsd_file on __kmem_cache_shutdown() -------------------------------------------------------------------- CPU: 4 UID: 0 PID: 764 Comm: sh Not tainted 6.12.0-rc3+ #1   dump_stack_lvl+0x53/0x70  slab_err+0xb0/0xf0  __kmem_cache_shutdown+0x15c/0x310  kmem_cache_destroy+0x66/0x160  nfsd_file_cache_shutdown+0xac/0x210 [nfsd]  nfsd_destroy_serv+0x251/0x2a0 [nfsd]  nfsd_svc+0x125/0x1e0 [nfsd]  write_threads+0x16a/0x2a0 [nfsd]  nfsctl_transaction_write+0x74/0xa0 [nfsd]  vfs_write+0x1a5/0x6d0  ksys_write+0xc1/0x160  do_syscall_64+0x5f/0x170  entry_SYSCALL_64_after_hwframe+0x76/0x7e  ==================================================================== BUG nfsd_file_mark (Tainted: G    B   W         ): Objects remaining nfsd_file_mark on __kmem_cache_shutdown() --------------------------------------------------------------------   dump_stack_lvl+0x53/0x70  slab_err+0xb0/0xf0  __kmem_cache_shutdown+0x15c/0x310  kmem_cache_destroy+0x66/0x160  nfsd_file_cache_shutdown+0xc8/0x210 [nfsd]  nfsd_destroy_serv+0x251/0x2a0 [nfsd]  nfsd_svc+0x125/0x1e0 [nfsd]  write_threads+0x16a/0x2a0 [nfsd]  nfsctl_transaction_write+0x74/0xa0 [nfsd]  vfs_write+0x1a5/0x6d0  ksys_write+0xc1/0x160  do_syscall_64+0x5f/0x170  entry_SYSCALL_64_after_hwframe+0x76/0x7e  To resolve this issue, cancel `nfsd_shrinker_work` using synchronous mode in nfs4_state_shutdown_net.","modified":"2026-10-01T11:03:32.660145627Z","published":"2024-11-05T18:15:15.080Z","upstream":["CVE-2024-50121"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50121"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50121.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50121.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50121.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}