Description
In the Linux kernel, the following vulnerability has been resolved:

lockd, nfsd: RCU-protect nlmsvc_ops dispatch

nlmsvc_ops is published by nfsd_lockd_init() and cleared by
nfsd_lockd_shutdown() with plain stores, while lockd dereferences
it unguarded from dispatch sites in fs/lockd/svcsubs.c. The pointer
targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's
.text, so a stale load after rmmod nfsd results in either a NULL
deref or a module-text use-after-free.

Declare nlmsvc_ops as __rcu, publish via rcu_assign_pointer(), clear
via RCU_INIT_POINTER() + synchronize_rcu(). Add a struct module
*owner field to nlmsvc_binding and pin the module across indirect
calls with try_module_get/module_put. When the binding is torn down,
fall back to fput() to avoid leaking struct file references.
Published: 2026-09-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a NULL pointer dere the nlmsvc_ops structure used by the NFS and lockd subsystems. The structure is published and cleared with plain memory stores, while lockd dereferences it without proper synchronization. When the nfsd module is unloaded while services are running, a stale load can trigger a kernel panic or module‑text use‑after‑free, abruptly terminating all NFS activities. The weakness is cataloged as CWE‑476.

Affected Systems

Any Linux system running a kernel that implements the NFS server and lockd components is affected. The vulnerability is present in mainline kernels before the commits that added RCU protection, and in custom or unpatched distributions that expose the nfsd_lockd_init() and nfsd_lockd_shutdown() functions.

Risk and Exploitability

The CVSS score of. The EPSS score is below 1 %, indicating current exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the local unloading or reloading of the nfsd module while the NFS or lockd service is running. A successful exploitation results in a kernel panic, causing a system restart or service outage, thus providing a catastrophic denial of service for all workloads relying on NFS.

Generated by OpenCVE AI on September 15, 2026 at 19:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a kernel that includes the RCU‑protect patch for nlmsvc_ops (commit 3c461a or 641e5e).
  • Do not unload or reload the nfsd module while the NFS or lockd service is running.
  • If an up‑to‑date kernel is not yet available, temporarily suspend or disable NFS and lockd services to prevent module unload until the patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsvc_ops is published by nfsd_lockd_init() and cleared by nfsd_lockd_shutdown() with plain stores, while lockd dereferences it unguarded from dispatch sites in fs/lockd/svcsubs.c. The pointer targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's .text, so a stale load after rmmod nfsd results in either a NULL deref or a module-text use-after-free. Declare nlmsvc_ops as __rcu, publish via rcu_assign_pointer(), clear via RCU_INIT_POINTER() + synchronize_rcu(). Add a struct module *owner field to nlmsvc_binding and pin the module across indirect calls with try_module_get/module_put. When the binding is torn down, fall back to fput() to avoid leaking struct file references.
Title lockd, nfsd: RCU-protect nlmsvc_ops dispatch
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:32.344Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89709

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.270

Modified: 2026-09-13T07:17:36.617

Link: CVE-2026-89709

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:24Z

Links: CVE-2026-89709 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses