Linux Kernel NFSv4 Deadlock Vulnerability During Layout Get Operations

Vulnerability

A vulnerability in the Linux kernel's NFSv4 implementation can lead to deadlocks when handling layout get operations. This issue arises because layout locks are held across multiple RPC calls, such as 'setattr()', which can trigger a recall and potentially cause a deadlock. The vulnerability has been addressed by ensuring that layout locks are released before making further RPC calls.

Impact

Exploitation of this vulnerability could lead to deadlocks, causing processes to hang indefinitely and potentially disrupting system operations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.