Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during close_lru reaping

An nfs4_openowner left on nn->close_lru after its final CLOSE keeps
its last closed stateid in oo_last_closed_stid, holding only a raw
pointer to its nfs4_client. The laundromat reaps timed-out entries,
drops nn->client_lock, and calls nfs4_put_stid(), which dereferences
the client through cl_lock. Nothing pins the client across that
window, so a concurrent force_expire_client() can free it and
nfs4_put_stid() reads freed memory. __destroy_client() hits the same
race, walking clp->cl_openowners without cl_lock.

Pin the client with cl_rpc_users before dropping client_lock, and
skip clients already expiring. __destroy_client() then cleans up its
own close_lru entries through release_last_closed_stateid(), so
teardown no longer races the laundromat.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from a use‑after‑free condition in the NFS server component of the Linux kernel. When a client is closed, the kernel retains a state identifier that keeps a dangling pointer to the NFS client object. The cleanup routine then dereferences this pointer while the client may already have been freed by a concurrent expiration path, leading to memory corruption. The severity is high, as a malicious actor can potentially execute arbitrary code with kernel privileges or, at a minimum, crash the kernel.

Affected Systems

All Linux kernel installations that employ the NFS server are potentially affected. The CVE data does not specify exact kernel versions, so users should consider any kernel that may run NFSD vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.8 indicates a severe risk. Although the EPSS score is less than 1%, meaning exploitation is currently unlikely, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access to an exposed NFS server, and the absence of a defensive workaround means a kernel upgrade is required for protection.

Generated by OpenCVE AI on September 18, 2026 at 04:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the fixed NFS handling code
  • Reboot the system to ensure the new kernel is fully loaded
  • If an immediate kernel upgrade is impossible, restrict NFS service exposure or remove the NFSD process from the affected host

Generated by OpenCVE AI on September 18, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final CLOSE keeps its last closed stateid in oo_last_closed_stid, holding only a raw pointer to its nfs4_client. The laundromat reaps timed-out entries, drops nn->client_lock, and calls nfs4_put_stid(), which dereferences the client through cl_lock. Nothing pins the client across that window, so a concurrent force_expire_client() can free it and nfs4_put_stid() reads freed memory. __destroy_client() hits the same race, walking clp->cl_openowners without cl_lock. Pin the client with cl_rpc_users before dropping client_lock, and skip clients already expiring. __destroy_client() then cleans up its own close_lru entries through release_last_closed_stateid(), so teardown no longer races the laundromat.
Title NFSD: Prevent client use-after-free during close_lru reaping
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:13.135Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90037

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.910

Modified: 2026-09-21T14:17:27.983

Link: CVE-2026-90037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses