Junglewise Threat Intelligence

CVE-2026-89660: Linux kernel NFSD use-after-free in client state revocation

CVE-2026-89660 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFS server (NFSD) component has a use-after-free vulnerability in its client state revocation logic that could allow an attacker to cause a crash or potentially execute code. When administrators revoke NFS client states, a race condition can cause the kernel to access freed client data structures, disrupting NFS service availability.

Technical details

A use-after-free vulnerability exists in the NFSD nfsd4_revoke_states() function when handling administrative client state revocation. The vulnerability occurs because nfsd4_revoke_states() temporarily drops the nn->client_lock while dereferencing the nfs4_client structure, creating a race condition where a concurrent client teardown (via force_expire_client()) can free the client before the revocation completes. The fix adds reference counting via cl_rpc_users and checks the client expiry status (cl_time == 0) under the lock to prevent dereferencing freed memory. An administrator or authenticated attacker triggering state revocation while clients disconnect can trigger this race, leading to kernel memory corruption or denial of service. A patch has been merged into the stable Linux kernel.

Affected products

  • Linux Linux kernel multiple versions (patches applied to linux-3.x through linux-7.x branches)

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Fix committed upstream by Chuck Lever; backported to stable kernels
  • 2026-09-11: advisory: CVE-2026-89660 published

References

Related threats