Executive brief
The Linux kernel's NFSv4 networking subsystem contains a memory management bug in its client allocation routine. When an NFSv4.0 client fails to initialize, a callback identifier remains registered in the kernel's internal data structure but points to freed memory. An attacker or local process performing NFSv4 callback operations could exploit this stale pointer to access or corrupt kernel memory, potentially leading to system crash or privilege escalation.
Technical details
This is a use-after-free (UAF) vulnerability in the NFSv4 client allocation code. The vulnerable component is nfs4_alloc_client() in fs/nfs/nfs4client.c, which allocates an NFSv4.0 callback identifier before completing client setup. If initialization fails after the callback identifier is allocated, the error path calls nfs_free_client() directly, bypassing nfs_put_client(), which normally removes the callback IDR entry. This leaves a stale pointer in cb_ident_idr pointing to freed memory. A subsequent NFSv4.0 callback lookup by callback identifier can retrieve and dereference this freed pointer, taking a reference to the freed client structure. The attack is reachable via NFSv4 network protocol operations; no special privileges are required to trigger callback operations. The fix makes the callback IDR removal helper nfs_cb_idr_remove() callable from the allocation error path to clean up the identifier before freeing the client.
Affected products
- Linux Linux kernel All versions supporting NFSv4.0 prior to fix (commit d05c2007b3d84ccba11dc6e9cb3202768cc72f14)
Timeline
- 2026-09-17: disclosed: CVE-2026-90151 published
- 2026-06-24: patched: Fix authored by Ruoyu Wang; committed upstream as d05c2007b3d84ccba11dc6e9cb3202768cc72f14
- 2026-09-14: other: Fix integrated into stable Linux kernel releases