Description
In the Linux kernel, the following vulnerability has been resolved:

lockd: pin next file across nlm_inspect_file lock-drop

nlm_traverse_files() pins the current file with f_count++ across
a mutex_unlock for nlm_inspect_file(), but nothing pins the saved
next pointer. A concurrent nlm_release_file() can kfree the next
file during the unlock window, and the iterator dereferences freed
memory on the next loop step.

Pin both current and next before the lock-drop. Advance by
swapping the pinned cursors at the end of each iteration so next
is always held alive across the unlock.

Always call nlm_file_release() after dropping the iteration pin,
regardless of whether the file matched the predicate. Use
nlm_file_inuse(), which does a live walk of the inode lock list,
rather than the cached f_locks field, so skipped files that never
ran nlm_inspect_file() are evaluated correctly.

Because every file in a hash bucket is now pinned and released,
files skipped by the is_failover_file predicate that have no
locks, blocks, shares, or external references are deleted during
traversal. The old code never evaluated skipped files for
cleanup. The new behavior is intentional: such files are stale
and should not persist in the table.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential arbitrary code execution
Action: Apply patch
AI Analysis

Impact

The lockd NFS lock daemon contains a use‑after‑free flaw in nlm_traverse_files. The code increments a reference, but the pointer to the next file is not pinned. A concurrent nlm_release_file can free that next file during the unlock window, and the iterator later dereferences freed memory, resulting in kernel memory corruption. An attacker that can trigger the race could cause a kernel crash or potentially execute arbitrary code at ring‑zero if the freed memory is reused maliciously.

Affected Systems

The vulnerability affects all Linux kernel builds that include the lockd component prior to the commit that introduces the pinning logic fix. Vendors listed as Linux:Linux indicate that any distribution using the upstream Linux kernel is potentially impacted. No specific release numbers are supplied, so the risk applies to any kernel running before the patch is applied, regardless of version.

Risk and Exploitability

Based on the description, the likely attack vector is a race condition that a local or privileged process can orchestrate against the lockd NFS lock daemon. The CVSS score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The flaw requires a carefully timed race, and based on the description it is inferred that the attack surface is largely limited to processes that can manipulate NFS locks. The vulnerability is not listed in the CISA KEV catalog, yet its high influence on kernel integrity warrants prompt action. If an attacker succeeds, the resulting kernel memory corruption can lead to a crash, denial of service, or a privilege escalation pathway to full system compromise.

Generated by OpenCVE AI on September 15, 2026 at 22:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the lockd use‑after‑free fix
  • Disable or stop the lockd service if NFS locking is not required
  • Monitor system logs for kernel panics or Oops events to detect unpatched exploitation

Generated by OpenCVE AI on September 15, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved next pointer. A concurrent nlm_release_file() can kfree the next file during the unlock window, and the iterator dereferences freed memory on the next loop step. Pin both current and next before the lock-drop. Advance by swapping the pinned cursors at the end of each iteration so next is always held alive across the unlock. Always call nlm_file_release() after dropping the iteration pin, regardless of whether the file matched the predicate. Use nlm_file_inuse(), which does a live walk of the inode lock list, rather than the cached f_locks field, so skipped files that never ran nlm_inspect_file() are evaluated correctly. Because every file in a hash bucket is now pinned and released, files skipped by the is_failover_file predicate that have no locks, blocks, shares, or external references are deleted during traversal. The old code never evaluated skipped files for cleanup. The new behavior is intentional: such files are stale and should not persist in the table.
Title lockd: pin next file across nlm_inspect_file lock-drop
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:21.375Z

Reserved: 2026-09-11T19:38:34.712Z

Link: CVE-2026-89485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:30.173

Modified: 2026-09-14T13:19:05.300

Link: CVE-2026-89485

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:39Z

Links: CVE-2026-89485 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference