{"id":"DEBIAN-CVE-2024-56779","details":"In the Linux kernel, the following vulnerability has been resolved:  nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur  The action force umount(umount -f) will attempt to kill all rpc_task even umount operation may ultimately fail if some files remain open. Consequently, if an action attempts to open a file, it can potentially send two rpc_task to nfs server.                     NFS CLIENT thread1                             thread2 open(\"file\") ... nfs4_do_open  _nfs4_do_open   _nfs4_open_and_get_state    _nfs4_proc_open     nfs4_run_open_task      /* rpc_task1 */      rpc_run_task      rpc_wait_for_completion_task                                      umount -f                                     nfs_umount_begin                                      rpc_killall_tasks                                       rpc_signal_task      rpc_task1 been wakeup      and return -512  _nfs4_do_open // while loop     ...     nfs4_run_open_task      /* rpc_task2 */      rpc_run_task      rpc_wait_for_completion_task  While processing an open request, nfsd will first attempt to find or allocate an nfs4_openowner. If it finds an nfs4_openowner that is not marked as NFS4_OO_CONFIRMED, this nfs4_openowner will released. Since two rpc_task can attempt to open the same file simultaneously from the client to server, and because two instances of nfsd can run concurrently, this situation can lead to lots of memory leak. Additionally, when we echo 0 to /proc/fs/nfsd/threads, warning will be triggered.                      NFS SERVER nfsd1                  nfsd2       echo 0 \u003e /proc/fs/nfsd/threads  nfsd4_open  nfsd4_process_open1   find_or_alloc_open_stateowner    // alloc oo1, stateid1                        nfsd4_open                         nfsd4_process_open1                         find_or_alloc_open_stateowner                         // find oo1, without NFS4_OO_CONFIRMED                          release_openowner                           unhash_openowner_locked                           list_del_init(&oo-\u003eoo_perclient)                           // cannot find this oo                           // from client, LEAK!!!                          alloc_stateowner // alloc oo2   nfsd4_process_open2   init_open_stateid   // associate oo1   // with stateid1, stateid1 LEAK!!!   nfs4_get_vfs_file   // alloc nfsd_file1 and nfsd_file_mark1   // all LEAK!!!                           nfsd4_process_open2                          ...                                      write_threads                                      ...                                      nfsd_destroy_serv                                       nfsd_shutdown_net                                        nfs4_state_shutdown_net                                         nfs4_state_destroy_net                                          destroy_client                                           __destroy_client                                           // won't find oo1!!!                                      nfsd_shutdown_generic                                       nfsd_file_cache_shutdown                                        kmem_cache_destroy                                        for nfsd_file_slab                                        and nfsd_file_mark_slab                                        // bark since nfsd_file1                                        // and nfsd_file_mark1                                        // still alive  ======================================================================= BUG nfsd_file (Not tainted): Objects remaining in nfsd_file on __kmem_cache_shutdown() -----------------------------------------------------------------------  Slab 0xffd4000004438a80 objects=34 used=1 fp=0xff11000110e2ad28 flags=0x17ffffc0000240(workingset|head|node=0|zone=2|lastcpupid=0x1fffff) CPU: 4 UID: 0 PID: 757 Comm: sh Not tainted 6.12.0-rc6+ #19 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 Call Trace:  \u003cTASK\u003e  dum ---truncated---","modified":"2026-09-15T09:03:17.507822336Z","published":"2025-01-08T18:15:18.793Z","upstream":["CVE-2024-56779"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56779"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56779.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56779.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56779.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}