Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent post-shutdown use-after-free in unlock_filesystem

Writing a filesystem path to /proc/fs/nfsd/unlock_filesystem runs
nfsd4_cancel_copy_by_sb() before nfsd_mutex is held and before the
handler confirms that nn->nfsd_serv is set. Once nfsd has shut down,
nfs4_state_destroy_net() has freed nn->conf_id_hashtbl but left the
pointer intact, so the cancel helper iterates freed slab memory as an
array of struct list_head and then dereferences a bogus nfs4_client
when it takes clp->async_lock. A local administrator holding
CAP_SYS_ADMIN can reach this use-after-free by stopping the server and
then writing to unlock_filesystem; KASAN reports a slab-use-after-free
read in nfsd4_cancel_copy_by_sb().

nfsd4_revoke_states() walks the same state tables and for that reason
already runs only under nfsd_mutex with nn->nfsd_serv confirmed
present. Move the async COPY cancel into that protected section so
every NFSv4 state-table walker on this path observes a running server.
Async copies exist only while the server runs, so gating the cancel on
nn->nfsd_serv loses nothing.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free memory corruption
Action: Apply patch
AI Analysis

Impact

A use‑after‑free flaw in the Linux kernel NFS server is triggered by writing to /proc/fs/nfsd/unlock_filesystem after the NFS daemon has stopped. The code path nfsd4_cancel_copy_by_sb() operates without holding the nfsd_mutex and before confirming nn->nfsd_serv, allowing it to dereference memory that has already been freed by nfs4_state_destroy_net(). This results in a slab‑use‑after‑free read that can corrupt kernel memory. A local administrator with CAP_SYS_ADMIN can trigger the flaw by stopping the server and then performing the write, as confirmed by KASAN reporting a slab‑use‑after‑free read.

Affected Systems

This flaw affects all Linux kernel implementations that expose the /proc/fs/nfsd/unlock_filesystem interface. The CPE identifier indicates the Linux kernel family and no specific affected version range is provided, so any kernel release prior to the patch is potentially impacted.

Risk and Exploitability

The CVSS score of 4.1 indicates low severity, and the EPSS score of < 1% reflects an extremely low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires local administrative privileges, the NFS daemon to be stopped, and the capability to write to /proc/fs/nfsd/unlock_filesystem. Given these strict conditions, the likelihood of real‑world exploitation is low, but the flaw can cause a system crash or memory corruption that damages kernel integrity.

Generated by OpenCVE AI on September 15, 2026 at 21:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the most recent Linux kernel update that includes the fix for the nfsd unlock_filesystem use‑after‑free.
  • If an immediate kernel upgrade is not possible, keep the NFS daemon running when using /proc/fs/nfsd/unlock_filesystem and avoid writing to the file after the server has been stopped.
  • Restrict write access to /proc/fs/nfsd/unlock_filesystem using security mechanisms such as SELinux or AppArmor so that only privileged processes can write to it.

Generated by OpenCVE AI on September 15, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem Writing a filesystem path to /proc/fs/nfsd/unlock_filesystem runs nfsd4_cancel_copy_by_sb() before nfsd_mutex is held and before the handler confirms that nn->nfsd_serv is set. Once nfsd has shut down, nfs4_state_destroy_net() has freed nn->conf_id_hashtbl but left the pointer intact, so the cancel helper iterates freed slab memory as an array of struct list_head and then dereferences a bogus nfs4_client when it takes clp->async_lock. A local administrator holding CAP_SYS_ADMIN can reach this use-after-free by stopping the server and then writing to unlock_filesystem; KASAN reports a slab-use-after-free read in nfsd4_cancel_copy_by_sb(). nfsd4_revoke_states() walks the same state tables and for that reason already runs only under nfsd_mutex with nn->nfsd_serv confirmed present. Move the async COPY cancel into that protected section so every NFSv4 state-table walker on this path observes a running server. Async copies exist only while the server runs, so gating the cancel on nn->nfsd_serv loses nothing.
Title NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:45:49.086Z

Reserved: 2026-09-11T19:38:34.744Z

Link: CVE-2026-89661

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:52.413

Modified: 2026-09-11T20:19:52.413

Link: CVE-2026-89661

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:49Z

Links: CVE-2026-89661 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference