Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup

nfs40_clean_admin_revoked() takes a stateid reference under
clp->cl_lock, drops nn->client_lock, and calls
nfsd4_drop_revoked_stid(), which dereferences the stateid's client
through s->sc_client->cl_lock. The stateid reference does not pin the
client, so a teardown racing the dropped lock can free the client
while nfsd4_drop_revoked_stid() is still using it.

This cleanup runs from the laundromat, so a periodic sweep can race
force_expire_client() driven by a write to the clients/<id>/ctl file.

Skip a client that is already expiring and otherwise pin it with
cl_rpc_users under client_lock before dropping the lock, matching
nfsd4_revoke_states().
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s NFS daemon contains a race condition that can free a NFS client while it is still in use by a background cleanup routine, causing a use‑after‑free and possible kernel memory corruption. The flaw is a classic denial attacker could crash the kernel or corrupt memory to execute arbitrary code.

Affected Systems

All Linux distributions that ship the Linux kernel with an unpatched nfsd component are affected. The flaw resides in the NFSv4.0 server code; any kernel that includes the nfsd module without the commit that fixes the race condition is vulnerable. No specific kernel versions were listed, so any release prior to the fix should be considered at risk.

Risk and Exploitability

The CVSS vector scores a 9.8, placing it in the critical zone. The EPSS score is less than 1%, indicating that while exploitation is unlikely now, the high severity and lack of a publicly known exploit mean prompt action is warranted. The flaw can be triggered by writing to a client control file such as clients/<id>/ctl; based on the description it is inferred that this requires root or equivalent privileges, so the vulnerability is likely exploitable only by privileged users. The vulnerability does not appear in the CISA KEV list, but the critical score and kernel impact make remediation a priority.

Generated by OpenCVE AI on September 15, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that includes the commit fixing the nfsd race condition (0ae0d2b5c5a1b39c0b3c15d96b32a5b0c).
  • Remove write permission from the clients/<id>/ctl file so that only privileged administrators the client teardown race can be triggered.
  • If the NFS service is not required, disable or uninstall the nfsd daemon to eliminate the vulnerable code from the running kernel.

Generated by OpenCVE AI on September 15, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfs40_clean_admin_revoked() takes a stateid reference under clp->cl_lock, drops nn->client_lock, and calls nfsd4_drop_revoked_stid(), which dereferences the stateid's client through s->sc_client->cl_lock. The stateid reference does not pin the client, so a teardown racing the dropped lock can free the client while nfsd4_drop_revoked_stid() is still using it. This cleanup runs from the laundromat, so a periodic sweep can race force_expire_client() driven by a write to the clients/<id>/ctl file. Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().
Title NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:40.908Z

Reserved: 2026-09-11T19:38:34.743Z

Link: CVE-2026-89658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:52.063

Modified: 2026-09-13T07:17:31.400

Link: CVE-2026-89658

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:46Z

Links: CVE-2026-89658 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference