Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during delegation revoke

A delegation stateid holds only a bare pointer to its owning
nfs4_client and does not keep it alive. The client survives its
stateids only because __destroy_client() drains cl_delegations and
cl_revoked before free_client() runs.

nfs4_laundromat() breaks that invariant: it unhashes an
expired delegation from cl_delegations, drops deleg_lock, then
revoke_delegation() relinks it onto cl_revoked under cl_lock. In that
window the delegation is on neither list, so client_has_state() can
report no remaining state.

Every teardown path first requires cl_rpc_users to be zero, but
the laundromat holds no such reference. A client whose recalled
delegation has just timed out can therefore reach free_client()
while revoke_delegation() is still about to dereference cl_lock,
a use-after-free.

Pin the client with cl_rpc_users across the revoke so teardown blocks
until it completes, then reap the delegation from cl_revoked. A client
already expiring reaps its own, so skip it and leave the delegation on
del_recall_lru.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in NFSd delegation handling
Action: Patch Now
AI Analysis

Impact

A use‑after‑free flaw is present in the Linux kernel’s NFS daemon when a delegation is revoked. The flaw allows an attacker to create a timing window where the delegation is removed from internal tracking while the client’s memory is freed, causing the daemon to dereference a freed memory block. The resulting kernel memory corruption can crash the NFS daemon or potentially allow an attacker to execute code in kernel context. This is a classic use‑after‑free vulnerability (CWE‑825), and based on the description, the likely attack vector is remote network access to an NFS client that can manipulate delegation timing.

Affected Systems

The affected component is the NFS server (nfsd) in the Linux kernel. All Linux kernel builds that do not include the recent patch fixing the delegation revoke code are vulnerable. The exact version range is not specified, so the commit adding the hardening is at risk.

Risk and Exploitability

With a CVSS score of 9.8, the vulnerability is considered critical. The EPSS score of < 1 % indicates a very low but non‑zero exploitation probability. Based on the description, the likely attack vector would involve remote network access to an NFS client capable of timing a delegation revoke, which could lead to denial of service or, if code execution is achieved, kernel‑level privilege escalation.

Generated by OpenCVE AI on September 15, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the NFS delegation use‑after‑free fix from commits 2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56, 3c0a53ee0b442348d8d2286d6960d3, or 4683ca76b3b7e5808338491c6eb3c20e6b4894d5.
  • After applying the patch, restart the nfsd service to load the updated kernel module.
  • If an immediate kernel upgrade is not possible, consider disabling or removing the NFS server until the patch can be applied, and monitor system logs for NFS crashes or memory corruption events.

Generated by OpenCVE AI on September 15, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client survives its stateids only because __destroy_client() drains cl_delegations and cl_revoked before free_client() runs. nfs4_laundromat() breaks that invariant: it unhashes an expired delegation from cl_delegations, drops deleg_lock, then revoke_delegation() relinks it onto cl_revoked under cl_lock. In that window the delegation is on neither list, so client_has_state() can report no remaining state. Every teardown path first requires cl_rpc_users to be zero, but the laundromat holds no such reference. A client whose recalled delegation has just timed out can therefore reach free_client() while revoke_delegation() is still about to dereference cl_lock, a use-after-free. Pin the client with cl_rpc_users across the revoke so teardown blocks until it completes, then reap the delegation from cl_revoked. A client already expiring reaps its own, so skip it and leave the delegation on del_recall_lru.
Title NFSD: Prevent client use-after-free during delegation revoke
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:40.335Z

Reserved: 2026-09-11T19:38:34.744Z

Link: CVE-2026-89659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:52.180

Modified: 2026-09-21T14:17:24.513

Link: CVE-2026-89659

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:47Z

Links: CVE-2026-89659 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference