Description
In the Linux kernel, the following vulnerability has been resolved:

NFS: Return a delegation the client fails to record

When an NFS server grants a delegation in an OPEN reply,
nfs_inode_set_delegation() records it on the client. However, three
of its error flows return without sending DELEGRETURN.

A delegation can be relinquished only by DELEGRETURN (RFC 8881
Section 20.2.4), so dropping one silently leaves the server believing
the client still holds it. If the server happens to recall that
delegation, the client answers CB_RECALL with NFS4ERR_BADHANDLE
because it has no record of the stateid. The server revokes the
delegation and moves it onto its cl_revoked list, because the client
never sends the FREE_STATEID that would drain it. Every subsequent
SEQUENCE reply then carries SEQ4_STATUS_RECALLABLE_STATE_REVOKED,
and the client's state manager loops issuing TEST_STATEID across its
delegations without ever clearing the condition.

The window is easy to reach now that a server offers a write
delegation on any write OPEN: a delegation recalled for one opener
races a re-open that the server answers with a fresh write
delegation.

Instead of dropping it, hand the delegation back during these error
flows.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via stale NFS delegations
Action: Immediate Patch
AI Analysis

Impact

An NFS server grants a delegation in an OPEN reply. The client records the delegation through nfs_inode_set_delegation(); however, some error paths exit without sending a DELEGRETURN message. As a result the server remains under the impression that the client still holds the delegation. When the server attempts to recall the delegation, the client, having never recorded the stateid, replies with NFS4ERR_BADHANDLE. The server then revokes the delegation and moves it onto its cl_revoked list, and any subsequent SEQUENCE reply includes SEQ4_STATUS_RECALLABLE_STATE_REVOKED. The client's state manager repeatedly issues TEST_STATEID operations against the revoked delegation, leading to a persistent loop.

Affected Systems

The affected systems are Linux kernel NFS server implementations. No specific kernel versions are provided, so the scope is all kernels that have not yet incorporated the change to correctly send DELEGRETURN on error paths. Administrators should consider all vulnerable NFS deployments at risk until the kernel is updated.

Risk and Exploitability

The CVSS score of 7.5 designates this vulnerability as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an attacker capable of sending NFS requests that trigger the error flows; no other prerequisites are specified. The risk remains moderate, and applying the fix promptly is recommended.

Generated by OpenCVE AI on September 20, 2026 at 03:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the NFS delegation fix.
  • If an immediate kernel upgrade is not possible, disable NFS delegations or restrict them to trusted client IP ranges to reduce the attack surface.
  • Monitor NFS server logs for repeated SEQ4_STATUS_RECALLABLE_STATE_REVOKED entries that indicate the state‑manager loop is occurring.

Generated by OpenCVE AI on September 20, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-773

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-892

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-892

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFS: Return a delegation the client fails to record When an NFS server grants a delegation in an OPEN reply, nfs_inode_set_delegation() records it on the client. However, three of its error flows return without sending DELEGRETURN. A delegation can be relinquished only by DELEGRETURN (RFC 8881 Section 20.2.4), so dropping one silently leaves the server believing the client still holds it. If the server happens to recall that delegation, the client answers CB_RECALL with NFS4ERR_BADHANDLE because it has no record of the stateid. The server revokes the delegation and moves it onto its cl_revoked list, because the client never sends the FREE_STATEID that would drain it. Every subsequent SEQUENCE reply then carries SEQ4_STATUS_RECALLABLE_STATE_REVOKED, and the client's state manager loops issuing TEST_STATEID across its delegations without ever clearing the condition. The window is easy to reach now that a server offers a write delegation on any write OPEN: a delegation recalled for one opener races a re-open that the server answers with a fresh write delegation. Instead of dropping it, hand the delegation back during these error flows.
Title NFS: Return a delegation the client fails to record
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:00.394Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90234

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:19.293

Modified: 2026-09-18T18:17:48.277

Link: CVE-2026-90234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-773

    Missing Reference to Active File Descriptor or Handle