Junglewise Threat Intelligence

CVE-2026-74730: Linux kernel NFS use-after-free in FREE_STATEID

CVE-2026-74730 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A use-after-free vulnerability exists in the Linux kernel's NFS (Network File System) implementation during FREE_STATEID operations. When a FREE_STATEID call is delayed, the kernel can attempt to access server structures that have already been cleaned up, potentially causing a system crash or allowing an attacker with network access to trigger a denial of service against NFS servers.

Technical details

The vulnerability is a use-after-free bug in the NFS v4 protocol handler (fs/nfs/nfs4proc.c), specifically in the nfs41_free_stateid() function. The root cause is that the 'struct nfs_server' reference is not pinned during asynchronous FREE_STATEID RPC operations; if the operation is delayed, the server structure can be deallocated while the RPC is still in flight. The fix increments the reference count of the nfs_server object at the start of FREE_STATEID (via nfs_sb_active()) and decrements it during cleanup (via nfs_sb_deactive()), ensuring the structure remains valid for the duration of the operation. The attack vector is network-based and requires the ability to trigger or delay NFS operations; no authentication is required beyond standard NFS access.

Affected products

  • Linux Linux kernel multiple versions (see NVD for full list)

Timeline

  • 2026-08-22: disclosed
  • 2026-06-30: patched: Upstream commit cf616096a0f3a2b60f7d68b6b39674a6867ded9c by Anna Schumaker

References

Related threats