Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4: remove callback IDR entry on client allocation failure

nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it
finishes setting up the client. If any later initialization step fails,
the error path frees the nfs_client directly with nfs_free_client(). That
bypasses nfs_put_client(), which is where the callback IDR entry is
removed during normal teardown.

A failed allocation can therefore leave cb_ident_idr pointing at a freed
nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the
stale pointer and take a reference to it.

Make the callback IDR removal helper callable by the allocation failure
path, and remove the callback identifier before freeing the client.

This was found by a local static-analysis checker for publish-before-free
lifetime bugs and confirmed by manual inspection.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free on NFSv4 callback identifier
Action: Immediate Patch
AI Analysis

Impact

A bug in the Linux kernel’s NFSv4 client allocation routine causes the callback identifier data structure (IDR) to be left pointing to a freed client object when later initialization steps fail. Subsequent NFSv4 callbacks that perform a lookup using this stale IDR entry will acquire a reference to the already‑freed client, resulting in a use‑after‑free condition. This can corrupt memory, crash the kernel, or provide an attacker with an execution vector, thereby compromising system integrity and availability.

Affected Systems

All Linux kernel releases that contain the NFSv4 client code, including both mainstream and LTS distributions, are affected. The CVE does not list specific version ranges, so any kernel version prior to the patch that introduces the removal of the callback IDR entry on allocation failure is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 reflects a high severity remote code execution risk. Although the EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation, the lack of a KEV listing does not diminish the need for immediate remediation. The vulnerability is internal to the kernel’s NFSv4 implementation; a direct attack vector would involve triggering an NFSv4 client allocation failure, which could potentially be achieved remotely by a client sending crafted requests or locally by an unprivileged user executing privileged system operations. The attack would require the ability to cause the failure path to be taken, after which the exploitation of the stale IDR entry could lead to arbitrary code execution.

Generated by OpenCVE AI on September 20, 2026 at 02:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the NFSv4 callback IDR removal fix found in commit 9bfdd0f (and its associated merges).
  • If a kernel upgrade is not immediately possible, disable NFSv4.0 on the affected host to eliminate the vulnerable code path.
  • Configure the system to reject or limit NFS client connections and monitor kernel logs for out‑of‑band “stale callback identifier” errors to detect possible exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later initialization step fails, the error path frees the nfs_client directly with nfs_free_client(). That bypasses nfs_put_client(), which is where the callback IDR entry is removed during normal teardown. A failed allocation can therefore leave cb_ident_idr pointing at a freed nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the stale pointer and take a reference to it. Make the callback IDR removal helper callable by the allocation failure path, and remove the callback identifier before freeing the client. This was found by a local static-analysis checker for publish-before-free lifetime bugs and confirmed by manual inspection.
Title NFSv4: remove callback IDR entry on client allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:26.660Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.057

Modified: 2026-09-18T18:17:44.250

Link: CVE-2026-90151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses