Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,
walks the NFSv4 client hash tables to revoke open state and cancel
async COPY operations. All three handlers gate that walk on
nn->nfsd_serv, but a listener added via portlist or netlink
listener_set sets nn->nfsd_serv before any nfsd thread starts.
nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the
walkers dereference a NULL table. A local administrator with
CAP_SYS_ADMIN can crash the kernel this way without ever starting the
server.

nn->nfsd_serv is set when the service is created, which precedes
table allocation. NFSD_NET_UP instead brackets the window where the
tables are live: set at the end of nfsd_startup_net() and cleared in
nfsd_shutdown_net() after they are freed, both under nfsd_mutex.
Gating the three unlock paths on NFSD_NET_UP fixes the startup-time
NULL dereference while preserving the earlier post-shutdown
use-after-free fix.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a flaw in the NFS daemon startup sequence: writing to /proc/fs/nfsd/unlock_filesystem or issuing the NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command triggers a walk of the NFSv4 client hash tables to revoke open state and cancel asynchronous copy operations. The handlers incorrectly gate this walk on nn->nfsd_serv, which is initialized before the hash table is allocated. The walk therefore dereferences a NULL pointer in nn->conf_id_hashtbl. A local administrator with CAP_SYS_ADMIN can trigger this path without ever starting the NFS server, resulting in a kernel panic and system crash. The primary impact is a denial of service that can affect all processes running on the host.

Affected Systems

This vulnerability affects all Linux kernel releases that implement the NFS server but have not been patched to introduce the NFSD_NET_UP guard. Distributions that ship the kernel with the NFS daemon (e.g., mainstream distros such as Ubuntu, Debian, Red Hat, SUSE) are potentially affected. No specific version range is provided by the CNA, therefore any unpatched kernel is at risk.

Risk and Exploitability

The CVSS score is not supplied, but the EPSS score is below 1 %, indicating a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, reducing the chance of observed malicious exploitation. Nonetheless, the flaw requires only local privileged access—a common scenario—so any attacker who can obtain CAP_SYS_ADMIN privileges can cause a system‑wide crash. Prompt remediation is advised even though the exploitation likelihood remains low.

Generated by OpenCVE AI on September 18, 2026 at 04:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the operating‑system provided kernel update that implements NFSD_NET_UP gating for the NFS daemon.
  • Reboot the system after updating the kernel to load the new code.
  • If an update cannot be applied immediately, disable the NFS daemon or remove the /proc/fs/nfsd/unlock_filesystem interface (e.g., by stopping the nfsd service or adjusting filesystem permissions) to prevent the null dereference from being triggered.

Generated by OpenCVE AI on September 18, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_NET_UP Writing to /proc/fs/nfsd/unlock_filesystem, or sending the NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command, walks the NFSv4 client hash tables to revoke open state and cancel async COPY operations. All three handlers gate that walk on nn->nfsd_serv, but a listener added via portlist or netlink listener_set sets nn->nfsd_serv before any nfsd thread starts. nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the walkers dereference a NULL table. A local administrator with CAP_SYS_ADMIN can crash the kernel this way without ever starting the server. nn->nfsd_serv is set when the service is created, which precedes table allocation. NFSD_NET_UP instead brackets the window where the tables are live: set at the end of nfsd_startup_net() and cleared in nfsd_shutdown_net() after they are freed, both under nfsd_mutex. Gating the three unlock paths on NFSD_NET_UP fixes the startup-time NULL dereference while preserving the earlier post-shutdown use-after-free fix.
Title NFSD: Guard admin state-revocation walks with NFSD_NET_UP
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:14.837Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90039

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.110

Modified: 2026-09-21T14:17:28.123

Link: CVE-2026-90039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses