Junglewise Threat Intelligence

CVE-2026-89661: Linux kernel NFSD use-after-free in unlock_filesystem

CVE-2026-89661 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFS server (NFSD) contains a use-after-free flaw in the /proc/fs/nfsd/unlock_filesystem handler. A local administrator can trigger this by stopping the NFS server and then writing to the unlock_filesystem file, causing the kernel to access freed memory and crash. This can lead to denial of service on systems providing NFS storage to clients.

Technical details

This is a use-after-free vulnerability in the NFSD subsystem's unlock_filesystem handler (fs/nfsd/nfsctl.c). The root cause is that nfsd4_cancel_copy_by_sb() was called before nfsd_mutex was held and before confirming nn->nfsd_serv was set. After the NFS server shuts down, nfs4_state_destroy_net() frees nn->conf_id_hashtbl but leaves the pointer intact. When the cancel helper later runs, it iterates over this freed memory as an array of list_head structures and dereferences an invalid nfs4_client pointer. A local admin with CAP_SYS_ADMIN can reach this by stopping the server and writing a filesystem path to /proc/fs/nfsd/unlock_filesystem, triggering a slab-use-after-free read. The fix moves nfsd4_cancel_copy_by_sb() inside the nfsd_mutex-protected section with nn->nfsd_serv confirmation, preventing access to freed state.

Affected products

  • Linux Linux kernel Multiple versions; patched by commit 292d915d3ba6fd15eeb88351fa10581683073109

Timeline

  • 2026-09-11: disclosed: CVE published on NVD
  • 2026-08-10: patched: Patch merged upstream by Chuck Lever
  • 2026-06-13: other: Patch authored by Chuck Lever

References

Related threats