Security advisory #56

Information

State: published
Published at: 2026-08-23 09:47:57 CEST
CVEs: CVE-2026-72472
Name: NFS file lock list use-after-free
Summary: English: Local privilege escalation
Česky: Lokální eskalace oprávnění
Description: English: A VPS administrator can mount an NFSv4 server and trigger lock recovery or delegation recall while another operation changes the same inode's file-lock list. The shared kernel could release its short spinlock during the traversal and later access a lock that had been freed. This use-after-free could give an attacker root inside the affected VPS. A more advanced exploit could potentially obtain root on the node. The reviewed technical evidence does not establish a complete node-control path or a mechanism for accessing another VPS. Failed attempts may crash the shared kernel and affect node availability. Kernel warnings that may indicate this bug was triggered are monitored.
Česky: Správce VPS může připojit server NFSv4 a vyvolat obnovu zámků nebo odvolání delegace ve chvíli, kdy jiná operace mění seznam zámků stejného inode. Sdílené jádro mohlo během průchodu uvolnit krátkodobý spinlock a později přistoupit k už uvolněnému zámku. Přístup do uvolněné paměti by mohl útočníkovi zajistit root uvnitř napadené VPS. Pokročilejší zneužití by mohlo potenciálně získat root na node. Analyzované technické podklady nepopisují úplný postup k ovládnutí node ani mechanismus pro přístup do jiného VPS. Neúspěšné pokusy mohou shodit sdílené jádro a ovlivnit dostupnost node. Varování jádra, která mohou naznačovat spuštění této chyby, jsou monitorována.
Response: English: The fix for this CVE is included starting with vpsAdminOS kernel live patch 6.12.95.2. NFS now protects long file-lock-list traversals with the inode read-write semaphore and moves blocking lock updates outside unsafe traversal contexts. Upstream Linux includes the fix in 6.12.97 and later stable releases.
Česky: Oprava této zranitelnosti je součástí vpsAdminOS kernel live patche od verze 6.12.95.2. NFS nyní chrání delší průchody seznamem zámků semaforem inode a přesouvá blokující změny zámků mimo nebezpečný kontext průchodu. Ve stabilních vydáních Linuxu je oprava obsažena od verze 6.12.97.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-06 04:45:59 CEST 2026-08-06 04:46:29 CEST
node20.prg mitigated 2026-08-06 04:46:05 CEST 2026-08-06 04:46:36 CEST
node21.prg mitigated 2026-08-06 04:46:08 CEST 2026-08-06 04:46:38 CEST
node22.prg mitigated 2026-08-06 04:45:54 CEST 2026-08-06 04:46:24 CEST
node23.prg mitigated 2026-08-06 04:46:04 CEST 2026-08-06 04:46:34 CEST
node24.prg mitigated 2026-08-06 04:46:25 CEST 2026-08-06 04:46:55 CEST
node25.prg mitigated 2026-08-06 04:46:16 CEST 2026-08-06 04:46:46 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-06 04:46:23 CEST 2026-08-06 04:46:53 CEST
node1.pgnd mitigated 2026-08-06 04:24:40 CEST 2026-08-06 04:25:10 CEST
node1.stg mitigated 2026-08-06 03:30:50 CEST 2026-08-06 03:31:39 CEST
node2.stg mitigated 2026-08-06 03:29:49 CEST 2026-08-06 03:30:14 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791