Description
In the Linux kernel, the following vulnerability has been resolved:

lockd: fix NULL dereference on lockowner allocation failure

nlmclnt_locks_init_private() installs NLM file lock operations even when
nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc()
then returns -ENOMEM, but the VFS still tears down the partially
initialized file_lock and calls locks_release_private().

That invokes nlmclnt_locks_release_private(), which dereferences
fl->fl_u.nfs_fl.owner and crashes because the owner was never installed.

Clear fl_ops before attempting to initialize the NLM private state, and
install the NLM lock operations only after a lockowner has been allocated
successfully.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Crash
Action: Immediate Patch
AI Analysis

Impact

A NULL pointer dereference occurs in the Linux kernel's NFS client lock subsystem when the allocation of a lockowner fails during nlmclnt_locks_init_private. The failure to install the lockowner initialized file_lock, causing nlmclnt_locks_release_private to dereference fl->fl_u.nfs_fl.owner, which was never set. This kernel crash produces a denial‑of‑service by bringing the system offline.

Affected Systems

Any Linux system that is running a kernel version containing the vulnerable lockd code is affected. The vulnerability exists until the patch commit that cleared the lock operations on allocation failure is applied. Systems with updated kernels that include the fix are not vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score of < 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw is triggered by a failed memory allocation in the NFS client lock code, so the likely attack vector is local or requires an NFS client that can force such failures, as inferred from the kernel context. Due to the kernel‑level nature of the fault, exploitation would need such a trigger, making the overall risk moderate.

Generated by OpenCVE AI on September 15, 2026 at 22:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a release that contains the patch commit (e.g., 07adfbb3...),
  • If a kernel update is unavailable, configure NFS mounts to use the 'nolock' option so that the NLM lock code path is bypassed during file locking.
  • Monitor system logs for kernel panic or NULL dereference messages and apply an updated kernel as soon as one becomes available.

Generated by OpenCVE AI on September 15, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private(). That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed. Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully.
Title lockd: fix NULL dereference on lockowner allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:38.740Z

Reserved: 2026-09-11T19:38:34.712Z

Link: CVE-2026-89484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:30.047

Modified: 2026-09-11T20:19:30.047

Link: CVE-2026-89484

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:38Z

Links: CVE-2026-89484 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses