Executive brief
The Linux kernel's NFS server (NFSD) contains a use-after-free vulnerability in the inter-server copy mount management code. When processing expired mount entries, the code temporarily releases a lock and continues iterating using a saved pointer that can be freed by concurrent operations, leading to memory corruption. An attacker with network access to an NFS server could trigger a kernel crash or potentially execute code.
Technical details
The vulnerability is a use-after-free in the nfsd4_ssc_expire_umount() function within the Linux kernel's NFS server implementation (fs/nfsd/nfs4state.c). The function walks a list of mount entries using list_for_each_entry_safe() to iterate while releasing the nfsd_ssc_lock during mntput() operations. While the current entry is protected by the nsui_busy flag, the saved next pointer (tmp) is not pinned and can be freed by concurrent nfsd4_ssc_cancel_dul() calls from other RPC threads during the lock-drop window, causing dereferencing of freed memory on the next iteration. The fix restarts the walk from the list head after each unlock window rather than relying on a saved next pointer. The vulnerability affects inter-server copy operations in NFS, which are network-accessible and require no authentication beyond normal NFS access controls. A patch is available in the Linux kernel stable trees.
Affected products
- Linux Linux kernel Multiple versions (2.6.11 through 6.x series affected; patched in stable branches)
Timeline
- 2026-09-11: disclosed: CVE-2026-89712 disclosed
- 2026-08-03: patched: Patch merged in kernel mainline (commit 036c1b182f4da65363e79ec0ac276edc6b7296e5)
- 2026-09-14: patched: Patch released in stable kernels via Greg Kroah-Hartman