Junglewise Threat Intelligence

CVE-2026-89659: Linux kernel NFSD use-after-free in delegation revoke

CVE-2026-89659 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFS server (NFSD) contains a use-after-free vulnerability in its delegation revocation logic. An attacker with network access to an NFS server could exploit a race condition to crash the kernel or potentially execute arbitrary code by triggering the premature cleanup of client data structures while delegation revocation is still in progress.

Technical details

The vulnerability is a use-after-free in the NFSD delegation revocation handler (nfs4_laundromat). A delegation stateid holds only a bare pointer to its owning nfs4_client without keeping it alive. The laundromat unhashes an expired delegation and drops deleg_lock, then revoke_delegation() relinks it to cl_revoked under cl_lock. During this window, the delegation is on neither list, so client_has_state() reports no remaining state. Teardown paths require cl_rpc_users to be zero, but the laundromat holds no such reference. This allows free_client() to run while revoke_delegation() still dereferences cl_lock. The fix pins the client with cl_rpc_users across the revoke, blocking teardown until delegation revocation completes. Network-accessible NFS servers are affected; no special authentication is required beyond basic NFS protocol communication.

Affected products

  • Linux Linux kernel Affected versions include linux-4.14.y through linux-6.9.y and other stable branches (commit 4683ca76b3b7e5808338491c6eb3c20e6b4894d5 or earlier)

Timeline

  • 2026-09-11: disclosed: Published in NVD and kernel stable tree
  • 2026-09-06: patched: Fix committed upstream by Chuck Lever (commit 4683ca76b3b7e5808338491c6eb3c20e6b4894d5)

References

Related threats