Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during export state revocation

nfsd4_revoke_export_states() has the same use-after-free as
nfsd4_revoke_states(): it drops nn->client_lock across
revoke_one_stid() and the following read of clp->cl_minorversion, but
the stateid reference it holds does not pin the client. A teardown
racing the dropped lock can free the client while revoke_one_stid()
still dereferences it.

exportfs -u drives this path through NFSD_CMD_UNLOCK_EXPORT, so an
administrator removing an export can race a client expiry.

Skip a client that is already expiring and otherwise pin it with
cl_rpc_users under client_lock before dropping the lock, matching
nfsd4_revoke_states().
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to memory corruption and potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

The changed code in the Linux kernel’s NFS server (NFSD) exposes a use‑after‑free flaw in the function that revokes client export states. When an export is revoked, the lock protecting the client structure is released before a reference to the client is safely held; this allows the client object to be freed while the revoke routine still dereferences it. The result is a memory corruption that an attacker could exploit to execute arbitrary code with the kernel's privileges.

Affected Systems

All versions of the Linux kernel that include NFSD, before the application of the patch that introduced the fix. The issue is present in the kernel source for the Linux distribution and is not limited to a specific vendor or distribution version.

Risk and Exploitability

This vulnerability receives a CVSS score of 9.8, indicating critical severity, but its EPSS score is under 1 %, suggesting a low probability of exploitation in current datasets. The flaw is not listed in CISA’s KEV catalog. Attacks would typically require an attacker to trigger an export revocation while clients are connected, which generally demands local or privileged administrative access. The lack of a publicly advertised exploitation vector further reduces immediate risk, but the high impact warrants prompt remediation.

Generated by OpenCVE AI on September 18, 2026 at 04:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the NFSD use‑after‑free fix.
  • Restrict the use of the exportfs command to trusted administrators and ensure exports are not removed while NFS clients are active.
  • If NFSv4 is not required for your environment, consider disabling the nfsv4 service until the patch has been applied.

Generated by OpenCVE AI on September 18, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export state revocation nfsd4_revoke_export_states() has the same use-after-free as nfsd4_revoke_states(): it drops nn->client_lock across revoke_one_stid() and the following read of clp->cl_minorversion, but the stateid reference it holds does not pin the client. A teardown racing the dropped lock can free the client while revoke_one_stid() still dereferences it. exportfs -u drives this path through NFSD_CMD_UNLOCK_EXPORT, so an administrator removing an export can race a client expiry. Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().
Title NFSD: Prevent client use-after-free during export state revocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:51.107Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.010

Modified: 2026-09-16T15:18:26.650

Link: CVE-2026-90038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses

No weakness.