Description
A use-after-free vulnerability was found in the 9P protocol implementation of NFS-Ganesha. The server does not protect the lifetime of file identifier (FID) objects when processing concurrent requests. An attacker can race a write operation against a close operation on the same FID, causing one worker thread to free the FID and its associated data while another thread continues to use it. This allows attacker-controlled data to be written into freed heap memory, which can result in a crash or potentially remote code execution. The 9P protocol handler does not implement authentication, so the vulnerability is reachable without credentials by any client with network access to the 9P listener.
Published: n/a
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Use‑after‑free leading to denial of service or potential remote code execution
Action: Patch Now
AI Analysis

Impact

A race condition in the 9P protocol implementation of NFS‑Ganesha allows an attacker to perform a write operation concurrently with a close operation on the same file identifier, freeing it while another thread continues to use it. This results in a use‑after‑free that lets attacker‑controlled data be written into freed heap memory, which can cause a crash or enable arbitrary code execution. The flaw is a classic CWE‑416 situation.

Affected Systems

The affected product is the NFS‑Ganesha server, specifically its 9P protocol handler. No specific version numbers are listed, so the vulnerability may affect all versions that have not been patched for the 9P use‑after‑free issue.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. Because the 9P handler lacks authentication, the flaw is reachable to any network client that can reach the 9P listener. An attacker can trigger the race condition remotely without credentials, making exploitation straightforward if they can observe two simultaneous 9P operations on the same file identifier.

Generated by OpenCVE AI on October 6, 2026 at 14:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NFS‑Ganesha to the latest version that contains the fix for the 9P use‑after‑free race condition.
  • Restrict network access to the 9P listener by configuring firewall rules or network segmentation to allow connections only from trusted hosts.
  • If authentication or encryption is supported for 9P, enable it to prevent unauthenticated clients from exploiting the vulnerability.

Generated by OpenCVE AI on October 6, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability was found in the 9P protocol implementation of NFS-Ganesha. The server does not protect the lifetime of file identifier (FID) objects when processing concurrent requests. An attacker can race a write operation against a close operation on the same FID, causing one worker thread to free the FID and its associated data while another thread continues to use it. This allows attacker-controlled data to be written into freed heap memory, which can result in a crash or potentially remote code execution. The 9P protocol handler does not implement authentication, so the vulnerability is reachable without credentials by any client with network access to the 9P listener.
Title nfs-ganesha: nfs-ganesha: 9P TWRITE/TCLUNK race condition use-after-free
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-05T00:00:00Z

Links: CVE-2026-105517 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T14:45:18Z

Weaknesses