REDHAT-BUG-2454844: High severity Linux Linux kernel (nfsd) vulnerability

Published Apr 3, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix heap overflow in NFSv4.0 LOCK replay cache

The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rpibuf[NFSD4REPLAYISIZE]) to store encoded operation responses. This size was calculated based on OPEN responses and does not account for LOCK denied responses, which include the conflicting lock owner as a variable-length field up to 1024 bytes (NFS4OPAQUELIMIT).

When a LOCK operation is denied due to a conflict with an existing lock that has a large owner, nfsd4encodeoperation() copies the full encoded response into the undersized replay buffer via readbytesfromxdrbuf() with no bounds check. This results in a slab-out-of-bounds write of up to 944 bytes past the end of the buffer, corrupting adjacent heap memory.

This can be triggered remotely by an unauthenticated attacker with two cooperating NFSv4.0 clients: one sets a lock with a large owner string, then the other requests a conflicting lock to provoke the denial.

We could fix this by increasing NFSD4REPLAYISIZE to allow for a full opaque, but that would increase the size of every stateowner, when most lockowners are not that large.

Instead, fix this by checking the encoded response length against NFSD4REPLAYISIZE before copying into the replay buffer. If the response is too large, set rpbuflen to 0 to skip caching the replay payload. The status is still cached, and the client already received the correct response on the original request.

Affected Software

1 affected component
Linux Linux kernel (nfsd)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Increase NFSD4_REPLAY_ISIZE to a value large enough for the full NFSv4.0 LOCK encoded replay payload, or apply the in-kernel fix that checks the encoded response length against NFSD4_REPLAY_ISIZE before copying into the replay buffer.

    Linux kernel nfsd NFSv4.0 replay cache NFSD4_REPLAY_ISIZE = (increase to accommodate full encoded response payload)
  2. Configuration

    Apply the bounds check behavior: when the encoded response is too large for the replay buffer, set rp_buflen to 0 to skip caching the replay response instead of copying beyond the buffer.

    Linux kernel nfsd NFSv4.0 replay cache rp_buflen = 0 (skip caching when response too large)

Event History

Apr 3, 2026
Data Sourced
via Red Hat·04:03 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2454844?

The severity of REDHAT-BUG-2454844 is classified as critical, due to the potential for heap overflow vulnerabilities.

2

How do I fix REDHAT-BUG-2454844?

To fix REDHAT-BUG-2454844, apply the latest patches provided by your Linux distribution that address this vulnerability.

3

Which versions of the Linux kernel are affected by REDHAT-BUG-2454844?

REDHAT-BUG-2454844 affects specific versions of the Linux kernel that utilize the NFSv4.0 LOCK replay cache.

4

What is the impact of the REDHAT-BUG-2454844 vulnerability?

The impact of the REDHAT-BUG-2454844 vulnerability includes potential denial of service and the possibility of remote code execution if exploited.

5

Has REDHAT-BUG-2454844 been patched?

Yes, REDHAT-BUG-2454844 has been patched in subsequent updates to the affected Linux kernel versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203