Executive brief
The Linux kernel's NFS server (nfsd) component failed to properly mark delegated file access permissions as freed when an administrator revoked them. This allows a use-after-free memory corruption bug to occur, where freed delegation objects are incorrectly re-added to a tracking list and later accessed during client cleanup, potentially allowing local attackers to crash the system or execute code with kernel privileges.
Technical details
A use-after-free vulnerability exists in the nfsd4_drop_revoked_stid() function in fs/nfsd/nfs4state.c. The function handles FREE_STATEID operations for admin-revoked delegations but fails to set the SC_STATUS_FREED flag before releasing the client lock (cl_lock). The revoke_delegation() function relies on this flag to detect whether FREE_STATEID has already processed a delegation; without it, the freed delegation object is incorrectly added to cl_revoked list via list_add(). This causes a use-after-free when cl_revoked is later traversed in __destroy_client() during NFS client cleanup. The fix sets SC_STATUS_FREED in the SC_STATUS_ADMIN_REVOKED path, matching the pattern already used in nfsd4_free_stateid(). Attack vector is local; no network exposure. Patch is available in upstream kernel.
Affected products
- Linux Linux kernel Multiple kernel versions (affects delegation handling in nfsd)
Timeline
- 2026-09-11: disclosed: CVE-2026-89703 published on NVD
- 2026-08-03: patched: Upstream fix committed by Chuck Lever
- 2026-09-07: patched: Fix included in stable kernel releases by Greg Kroah-Hartman