Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: defer vfree of compound ops to fix rpc_status UAF

The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums out of
args->ops[]. But args->ops is a separate vmalloc buffer freed
synchronously by vfree() in nfsd4_release_compoundargs() at the end
of every compound. The dumpit's rcu_read_lock pins the svc_rqst
struct itself (freed via kfree_rcu), but nothing defers the vfree
of the ops buffer across the RCU grace period. A concurrent compound
completion can therefore free the buffer while the dumpit is reading
it — a use-after-free on vmalloc memory.

The trailing seqcount recheck (smp_load_acquire of rq_status_counter)
cannot undo a load that already retired against freed memory.

Fix by replacing vfree(args->ops) with kvfree_rcu_mightsleep(), which
defers the free until after an RCU grace period. This makes the
existing rcu_read_lock in the dumpit sufficient to protect the read.
The tradeoff is that completed compound ops buffers (up to
200 * sizeof(struct nfsd4_op)) persist in memory slightly longer,
across one grace period, before being reclaimed.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free leading to kernel memory corruption
Action: Patch promptly
AI Analysis

Impact

The Linux kernel’s NFSv4 NFS server contains a netlink command that holds an RCU read lock and reads operation numbers from a vmalloc buffer. The buffer is freed synchronously with vfree at the end of each compound operation, but the free is not deferred across the RCU grace period. If a compound operation completes while the netlink dump is still reading the buffer, the buffer may be freed and an attacker can read from freed memory, resulting in a use‑after‑free (CWE‑825) that corrupts kernel memory.

Affected Systems

Any Linux kernel that has not implemented the commit that replaces vfree(args->ops in nfsd4_release_compoundargs is potentially affected. The advisory does not specify a version range, so all kernels lacking this commit, regardless of release, are at risk.

Risk and Exploitability

The CVSS score of 7.8 signals high severity, while the EPSS score of <1% indicates a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the rpc_status netlink interface to be reachable and an NFSv4 service to be running. The or higher privilege is required; therefore the required privilege level is unknown.

Generated by OpenCVE AI on September 15, 2026 at 20:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel that contains the commit replacing vfree(args->ops with kvfree_rcu_mightsleep to eliminate the use‑after‑free flaw (CWE‑825).
  • Limit or remove access to the rpc_status netlink command for unprivileged users to reduce the attack surface.
  • If the NFSv4 compound operation feature is not needed, disable NFSv4 to eliminate the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status UAF The rpc_status netlink dumpit walks every in-flight svc_rqst under rcu_read_lock and, for NFSv4 requests, reads opnums out of args->ops[]. But args->ops is a separate vmalloc buffer freed synchronously by vfree() in nfsd4_release_compoundargs() at the end of every compound. The dumpit's rcu_read_lock pins the svc_rqst struct itself (freed via kfree_rcu), but nothing defers the vfree of the ops buffer across the RCU grace period. A concurrent compound completion can therefore free the buffer while the dumpit is reading it — a use-after-free on vmalloc memory. The trailing seqcount recheck (smp_load_acquire of rq_status_counter) cannot undo a load that already retired against freed memory. Fix by replacing vfree(args->ops) with kvfree_rcu_mightsleep(), which defers the free until after an RCU grace period. This makes the existing rcu_read_lock in the dumpit sufficient to protect the read. The tradeoff is that completed compound ops buffers (up to 200 * sizeof(struct nfsd4_op)) persist in memory slightly longer, across one grace period, before being reclaimed.
Title nfsd: defer vfree of compound ops to fix rpc_status UAF
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:14.771Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89690

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.030

Modified: 2026-09-13T07:17:34.850

Link: CVE-2026-89690

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:10Z

Links: CVE-2026-89690 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference