Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: hold rcu across localio cmpxchg retry

nfsd_file objects are freed via call_rcu (filecache.c:296), and
nfsd_file_slab is created without SLAB_TYPESAFE_BY_RCU
(KMEM_CACHE(nfsd_file, 0) at filecache.c:789), so the slab page
backing a freed nfsd_file becomes freely reclaimable once the RCU
grace period elapses.

The again: retry block in nfsd_open_local_fh() loads a pointer with
cmpxchg and then calls nfsd_file_get(new) (which is
refcount_inc_not_zero) without holding rcu_read_lock. The sole caller
nfs_open_local_fh() drops rcu_read_lock before invoking this helper,
so no outer reader-side critical section covers the load.

CPU 0 (nfsd_open_local_fh) CPU 1 (nfsd_file_put_local)
----- -----
new = cmpxchg(pnf, NULL, ...)
nf = xchg(pnf, NULL)
nfsd_file_put(nf)
last ref -> call_rcu()
/* grace period elapses;
slab page recycled */
nfsd_file_get(new)
refcount_inc_not_zero(&new->nf_ref)
/* operates on recycled memory */

A non-zero word at the nf_ref offset of the recycled object makes the
refcount bump appear to succeed, and the caller then dereferences
new->nf_net and new->nf_file out of freed memory.

Fix by taking rcu_read_lock() immediately before the cmpxchg and
releasing it on all three exits of the if (new) block: the goto-again
retry, the lost-race cleanup path, and the install-succeeded path.
nfsd_file_put() and nfsd_net_put() stay outside the RCU section so
they remain free to block.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a use‑after‑free flaw in the NFS server (nfsd) where a freed nfsd_file object can be accessed after an RCU grace period. When a client opens a local file handle, the kernel performs a cmpxchg on the nfsd_file pointer and then increments its reference count without holding an rcu_read_lock. If the object has already been freed and the slab page reclaimed, the refcount bump succeeds on stale memory and the kernel dereferences fields that belong to a reclaimed buffer. This can lead to a kernel crash or, in the best case for the attacker, execution of code with kernel privileges. The severity is high because it is a kernel‑space use‑after‑free that can provide full system compromise.

Affected Systems

Any Linux distribution running an NFS server (nfsd) on a kernel version that has not yet applied the patch fixing the RCU handling bug is affected. The flaw was resolved in the downstream kernel update that followed the public disclosure, but all prior releases remain vulnerable. Vendors include all major Linux distributions that ship the upstream kernel.

Risk and Exploitability

The CVSS score of 7.8 reflects a confluence of high impact and lack of necessity for privileged local access. The EPSS score below 1% indicates that, as of the last update, only a very small fraction of monitored traffic patterns targeted this weakness, but the flaw is still considered exploitable by an attacker with network access to an NFS client interface. The vulnerability is not listed in the CISA KEV catalog, which means no known active exploits have been identified yet. However, the remote attack vector is straightforward: an attacker sends a crafted NFS open request to a server that competes for the same nfsd_file slot, triggering the race that leads to a use‑after‑free. Once triggered, the kernel can crash or yield control to arbitrary code.

Generated by OpenCVE AI on September 15, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest LinuxCU handling fix; this is the authoritative remedy for the flaw.
  • Until the patch is applied, stop the NFS server or block NFS traffic (ports 2049 for NFSv4, 111 for portmapper) to prevent exposure of the vulnerable code path.
  • After updating the kernel, reboot the host and verify that the NFS service starts normally; monitor system logs for any lingering use‑after‑free related errors.

Generated by OpenCVE AI on September 15, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: hold rcu across localio cmpxchg retry nfsd_file objects are freed via call_rcu (filecache.c:296), and nfsd_file_slab is created without SLAB_TYPESAFE_BY_RCU (KMEM_CACHE(nfsd_file, 0) at filecache.c:789), so the slab page backing a freed nfsd_file becomes freely reclaimable once the RCU grace period elapses. The again: retry block in nfsd_open_local_fh() loads a pointer with cmpxchg and then calls nfsd_file_get(new) (which is refcount_inc_not_zero) without holding rcu_read_lock. The sole caller nfs_open_local_fh() drops rcu_read_lock before invoking this helper, so no outer reader-side critical section covers the load. CPU 0 (nfsd_open_local_fh) CPU 1 (nfsd_file_put_local) ----- ----- new = cmpxchg(pnf, NULL, ...) nf = xchg(pnf, NULL) nfsd_file_put(nf) last ref -> call_rcu() /* grace period elapses; slab page recycled */ nfsd_file_get(new) refcount_inc_not_zero(&new->nf_ref) /* operates on recycled memory */ A non-zero word at the nf_ref offset of the recycled object makes the refcount bump appear to succeed, and the caller then dereferences new->nf_net and new->nf_file out of freed memory. Fix by taking rcu_read_lock() immediately before the cmpxchg and releasing it on all three exits of the if (new) block: the goto-again retry, the lost-race cleanup path, and the install-succeeded path. nfsd_file_put() and nfsd_net_put() stay outside the RCU section so they remain free to block.
Title nfsd: hold rcu across localio cmpxchg retry
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:52.764Z

Reserved: 2026-09-11T19:38:34.746Z

Link: CVE-2026-89670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:53.517

Modified: 2026-09-13T07:17:32.670

Link: CVE-2026-89670

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:55Z

Links: CVE-2026-89670 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference