Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations

nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked
delegations but does not set SC_STATUS_FREED before releasing cl_lock.
revoke_delegation() uses this flag to detect whether FREE_STATEID has
already processed the delegation -- without it, the freed delegation is
added to cl_revoked via list_add(), producing a use-after-free when
cl_revoked is later traversed in __destroy_client().

The SC_STATUS_REVOKED path in nfsd4_free_stateid() (line 7983) already
sets SC_STATUS_FREED correctly. Apply the same pattern to the
SC_STATUS_ADMIN_REVOKED path in nfsd4_drop_revoked_stid().
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel crash and NFS denial of service
Action: Apply Patch
AI Analysis

Impact

nfsd4_drop_revoked_stid processes FREE_STATEID for admin‑revoked delegations but fails to set the SC_STATUS_FREED flag before releasing cl_lock. Without this flag, the freed delegation is readded to the revoked list, causing a use‑after cleanup. The flaw can crash the kernel and deny service to NFS clients.

Affected Systems

All Linux kernel releases that have not incorporated commit 1e479576 are vulnerable. The affected products are all distributions that ship the legacy Linux kernel without the SC_STATUS_FREED fix under the vendor identifier Linux:Linux.

Risk and Exploitability

The CVSS score of 9.8 classifies this vulnerability as critical severity. The EPSS score of < 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based: an attacker would need an NFSv4 client capable of sending a FREE_STATEID request for an admin‑revoked delegation to the vulnerable NFS server. Because control is limited to a specific NFS protocol operation, remote code execution is not possible; the primary impact is a kernel crash leading to denial of service.

Generated by OpenCVE AI on September 15, 2026 at 19:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes commit 1e479576, which sets SC_STATUS_FREED before releasing cl_lock.
  • Reboot the system to load the updated kernel and ensure the NFS service runs with the patch applied.
  • If patching cannot be performed immediately, block or disable NFSv4 traffic, for example by blocking port 2049 in the firewall or disabling the nfsd service, to limit exposure until the kernel is updated.

Generated by OpenCVE AI on September 15, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked delegations but does not set SC_STATUS_FREED before releasing cl_lock. revoke_delegation() uses this flag to detect whether FREE_STATEID has already processed the delegation -- without it, the freed delegation is added to cl_revoked via list_add(), producing a use-after-free when cl_revoked is later traversed in __destroy_client(). The SC_STATUS_REVOKED path in nfsd4_free_stateid() (line 7983) already sets SC_STATUS_FREED correctly. Apply the same pattern to the SC_STATUS_ADMIN_REVOKED path in nfsd4_drop_revoked_stid().
Title nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:24.763Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:57.537

Modified: 2026-09-13T07:17:35.860

Link: CVE-2026-89703

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:20Z

Links: CVE-2026-89703 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference