Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()

When nfs4_add_lease() races with a delegation return, it calls
nfs4_delete_lease() to clean up. Previously, it passed priv,
which can legitimately be NULL. Passing a NULL priv eventually
leads to a NULL pointer dereference in generic_setlease().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The bug occurs when the NFSv4 add‑lease function races with a delegation return, causing nfs4_delete_lease to be invoked with a NULL privilege pointer. This incorrect argument leads to a null pointer dereference inside generic_setlease, which can trigger a kernel panic and result in a denial‑of‑service situation. The primary impact is a crash of the kernel that brings down the affected system. Based on the description, the race condition requires NFS traffic that an attacker can control, so the likely attack vector involves precise timing of NFS operations to trigger the race.

Affected Systems

All Linux kernels that include NFSv4 support and that have not yet applied the fix are vulnerable. This includes any distribution using the upstream Linux kernel before the commit documented in the provided patch links. The affected product family is Linux:Linux, as indicated by the vendor list and the CPE string.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalogue, indicating a low likelihood of exploitation in the wild. Nevertheless, the race condition required for exploitation involves precise timing of NFS operations, increasing attack complexity. If an attacker succeeds, the outcome is a kernel panic that terminates services and causes a denial‑of‑service. Administrators should therefore patch promptly while monitoring NFS activity.

Generated by OpenCVE AI on September 20, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the nfs4_add_lease fix, as indicated by the commit logs.
  • After updating, reboot or reload the NFS module to ensure the patched code is loaded.
  • If patching cannot be performed immediately, consider disabling NFSv4 delegations to mitigate the race condition until a proper fix is applied.

Generated by OpenCVE AI on September 20, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() When nfs4_add_lease() races with a delegation return, it calls nfs4_delete_lease() to clean up. Previously, it passed priv, which can legitimately be NULL. Passing a NULL priv eventually leads to a NULL pointer dereference in generic_setlease().
Title NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:42.992Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.710

Modified: 2026-09-17T17:17:07.710

Link: CVE-2026-90148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses