Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix clock domain mismatch in clients_still_reclaiming()

clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it against
ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot).
The comparison is always false — it would take ~54 years of uptime
for BOOTTIME to exceed the REALTIME-derived deadline.

This means any client can hold the server in grace indefinitely by
sending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim
operations for all other clients.

Add boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time
and use it for the deadline computation. boot_time (CLOCK_REALTIME)
is preserved for its cl_boot clientid-nonce role.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service on NFS server availability
Action: Patch Immediately
AI Analysis

Impact

The NFS daemon contains a function that checks whether a client has finished reclaiming previous resources. That function builds a deadline from the system clock based on the real‑time clock but compares it to the boot‑time clock. Because the two clocks are measured on different origins, the comparison is always false, so a client can keep the server in a grace period forever. The attacker can trigger this by sending CLAIM_PREVIOUS OPEN requests. As a result all non‑reclaim operations for every client are blocked and the NFS service effectively stops responding, creating a denial of service. The flaw is a classic clock domain mismatch (CWE‑1025).

Affected Systems

The vulnerability exists in the Linux kernel itself, and therefore applies to any Linux distribution that runs the NFS server built into the kernel. No specific kernel version is identified, so all releases with the clients_still_reclaiming function that have not applied the committed patch are potentially impacted.

Risk and Exploitability

The CVSS vulnerability as high severity. The EPSS score is below 1 %, indicating that exploitation is unlikely but not impossible. The flaw is not listed in the CISA KEV catalog. Exploitation required only network access to the NFS interface; no special authentication or elevated privileges are needed. A remote host on the NFS network can send CLAIM_PREVIOUS OPEN requests and trigger the denial of service.

Generated by OpenCVE AI on September 15, 2026 at 20:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the nfsd clients_still_reclaiming fix
  • Restart the NFS server after upgrading the kernel so the patched code is loaded
  • If the patch is not immediately available, temporarily disable client reclamation on the server to prevent clients from holding the grace period

Generated by OpenCVE AI on September 15, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1025
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but compares it against ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot). The comparison is always false — it would take ~54 years of uptime for BOOTTIME to exceed the REALTIME-derived deadline. This means any client can hold the server in grace indefinitely by sending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim operations for all other clients. Add boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time and use it for the deadline computation. boot_time (CLOCK_REALTIME) is preserved for its cl_boot clientid-nonce role.
Title nfsd: fix clock domain mismatch in clients_still_reclaiming()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:47.090Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:55.420

Modified: 2026-09-21T14:17:25.203

Link: CVE-2026-89685

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:07Z

Links: CVE-2026-89685 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-1025

    Comparison Using Wrong Factors