Junglewise Threat Intelligence

CVE-2026-89690: Linux kernel nfsd use-after-free in rpc_status netlink handling

CVE-2026-89690 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NFS server (nfsd) component has a use-after-free vulnerability in the rpc_status netlink interface that reports in-flight NFS requests. An attacker with the ability to trigger concurrent NFS requests and netlink status queries can cause the kernel to read freed memory, potentially leading to information disclosure or a denial of service. This affects systems running an NFS server that expose rpc_status netlink monitoring.

Technical details

The vulnerability is a use-after-free on vmalloc memory in the nfsd NFSv4 compound operation handler. The rpc_status netlink dumpit function walks in-flight requests under RCU read lock and reads operation numbers from args->ops[], but this buffer is synchronously freed via vfree() in nfsd4_release_compoundargs() when a request completes. The RCU read lock only protects the svc_rqst struct itself (freed via kfree_rcu), not the separately allocated ops buffer. A race condition allows the dumpit function to read the ops buffer after it has been freed. The fix defers the vfree() using kvfree_rcu_mightsleep(), ensuring the buffer persists until after an RCU grace period, protecting concurrent readers. The vulnerability requires local network access to trigger NFS requests and access the rpc_status netlink interface.

Affected products

  • Linux Linux kernel 2.6.11 and later, including 3.x, 4.x, 5.x, 6.x, 7.x series

Timeline

  • 2026-09-11: disclosed: CVE-2026-89690 published
  • 2026-09-07: patched: Fix committed upstream by Jeff Layton and merged by Greg Kroah-Hartman

References

Related threats