Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock

nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with
list_for_each_entry_safe(ni, tmp, ...). For each expired entry it
sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the
source vfsmount, then reacquires the lock to list_del + kfree the
entry and continue iterating via the macro's saved tmp pointer.

The nsui_busy flag protects the current ni from concurrent
nfsd4_ssc_setup_dul() finders during the lock-drop window, but it
does not pin tmp. Another nfsd RPC thread that fails its source-
server mount and reaches nfsd4_ssc_cancel_dul() will, during that
same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount
item, and release the lock. If that item is the saved tmp of the
expire walk, the next iteration dereferences a freed
nfsd4_ssc_umount_item.

Restart the walk from the head after the mntput() unlock window so
no saved next pointer survives the lock-drop. The list is bounded
by the number of active inter-server source mounts (typically small)
and the expire delayed-work runs periodically rather than per-IO,
so the restart is cheap.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in Linux NFS kernel
Action: Patch
AI Analysis

Impact

This vulnerability targets the NFSD subsystem in the Linux kernel. During an expiration release the nfsd_ssc_lock is dropped and later reacquired to delete an expired entry. Because the walk uses a safe iteration macro that does not retain concurrent thread may free that element while the lock is released. The next iteration then dereferences a freed structure, causing a use‑kernel crash or other undefined memory corruption. No privilege escalation or data exposure is explicitly claimed in the description.

Affected Systems

All Linux kernel builds that include the NFSD module prior to the patch are potentially affected. The CNA data lists the generic Linux kernel CPE without version information, so any kernel version lacking the recent patch falls under risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the EPSS score of <1% indicates a very low exploitation probability at the current time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely triggered via NFS client operations that cause a source‑server mount to fail during the lock‑drop window, leading to a race the risk remains contained to environments where an attacker can influence NFS mount activity, potentially causing a kernel crash and denial of service.

Generated by OpenCVE AI on September 15, 2026 at 20:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the patch for the NFSD use‑after‑free.
  • If an immediate kernel update is not feasible, unload or disable the NFSD kernel module to eliminate the vulnerable code path.
  • Reboot the system after applying the update or after unloading the module to clear any residual state and confirm normal operation.

Generated by OpenCVE AI on September 15, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.
Title NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:11.760Z

Reserved: 2026-09-11T19:38:34.751Z

Link: CVE-2026-89712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:58.620

Modified: 2026-09-14T13:19:21.077

Link: CVE-2026-89712

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:27Z

Links: CVE-2026-89712 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference