Description
In the Linux kernel, the following vulnerability has been resolved:

NFSD: Release the export reference when reaping open stateids

nfs4_put_stid() releases the svc_export tracked in
nfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and
lock stateids by calling ->sc_free() directly, bypassing that path.
An open stateid takes an sc_export reference in nfs4_open() and a
lock stateid takes its own in init_lock_stateid(); both reach
free_ol_stateid_reaplist() through their normal teardown, the open
stateid via release_open_stateid() and the lock stateid via
nfsd4_release_lockowner(), each through put_ol_stateid_locked().
The reference is therefore never dropped, pinning the export and
blocking unmount for the lifetime of the stateid.

Release sc_export in free_ol_stateid_reaplist() the way
nfs4_put_stid() does. ->sc_free() runs once per stateid, and a
stateid reaches free_ol_stateid_reaplist() or nfs4_put_stid() but
never both, so the reference is dropped exactly once. Revoked
stateids reach this path with sc_export already cleared by
drop_stid_export(), so they are skipped rather than double-freed.

nfs4_put_stid() itself read sc_export before acquiring cl_lock.
drop_stid_export() clears that field and releases the reference
under cl_lock, so a concurrent revocation could drop the export in
the window between the read and the final put, releasing the same
reference twice. Read sc_export while cl_lock is held so the two
paths serialize and the reference is released exactly once.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource leak causing denial of service by preventing export unmount in NFSd
Action: Apply patch
AI Analysis

Impact

A reference to the NFS export (sc_export) is never released when reaping open or lock state identifiers. The reference count is never decremented, which pins the export and blocks its unmount for the entire lifetime of the state identifier. As a result the NFS export cannot be safely removed, leading to a denial‑of‑service condition in which a client or administrator cannot cleanly disconnect the service. The issue is a classic resource‑management flaw that can be triggered by normal NFS state‑id usage.

Affected Systems

The vulnerability exists in the Linux kernel, affecting all kernel versions that include the original NFSv4 state‑id handling code. No specific release is listed, but the flaw applies to any Linux system running NFSd that has not yet incorporated the reference‑count fix. Affected vendors include the upstream Linux distribution maintainers who ship the kernel.

Risk and Exploitability

The specific CVSS score is not provided in the data, and the EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, and no public exploits are documented. An attacker would need to create or manipulate NFS state identifiers—either through a remote NFS client or by leveraging local privileged access—to keep an export reference pinned and prevent unmount operations. Because the flaw requires the kernel to maintain the state and does not involve arbitrary code execution, the risk is moderate with a low likelihood of exploitation based on the available metrics.

Generated by OpenCVE AI on September 19, 2026 at 03:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the reference‑release fix for NFSd state identifiers (commit 6480bd703684ed3f760e9e36c4a699033c0806ae or later).
  • Rebuild the kernel from a source tree that includes the patch if your distribution does not yet provide a newer release and reboot into the updated kernel to close the export reference leak.
  • If immediate kernel upgrade is not possible, restrict NFS client access or temporarily disable NFS services while monitoring for abnormal state‑id accumulation and plan a timely upgrade.

Generated by OpenCVE AI on September 19, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-668

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSD: Release the export reference when reaping open stateids nfs4_put_stid() releases the svc_export tracked in nfs4_stid.sc_export, but free_ol_stateid_reaplist() frees open and lock stateids by calling ->sc_free() directly, bypassing that path. An open stateid takes an sc_export reference in nfs4_open() and a lock stateid takes its own in init_lock_stateid(); both reach free_ol_stateid_reaplist() through their normal teardown, the open stateid via release_open_stateid() and the lock stateid via nfsd4_release_lockowner(), each through put_ol_stateid_locked(). The reference is therefore never dropped, pinning the export and blocking unmount for the lifetime of the stateid. Release sc_export in free_ol_stateid_reaplist() the way nfs4_put_stid() does. ->sc_free() runs once per stateid, and a stateid reaches free_ol_stateid_reaplist() or nfs4_put_stid() but never both, so the reference is dropped exactly once. Revoked stateids reach this path with sc_export already cleared by drop_stid_export(), so they are skipped rather than double-freed. nfs4_put_stid() itself read sc_export before acquiring cl_lock. drop_stid_export() clears that field and releases the reference under cl_lock, so a concurrent revocation could drop the export in the window between the read and the final put, releasing the same reference twice. Read sc_export while cl_lock is held so the two paths serialize and the reference is released exactly once.
Title NFSD: Release the export reference when reaping open stateids
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:41.898Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:19.533

Modified: 2026-09-17T17:17:19.533

Link: CVE-2026-90236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:00:07Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-668

    Exposure of Resource to Wrong Sphere