๐Ÿ” CVE Alert

CVE-2026-89485

CRITICAL 9.8

lockd: pin next file across nlm_inspect_file lock-drop

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved next pointer. A concurrent nlm_release_file() can kfree the next file during the unlock window, and the iterator dereferences freed memory on the next loop step. Pin both current and next before the lock-drop. Advance by swapping the pinned cursors at the end of each iteration so next is always held alive across the unlock. Always call nlm_file_release() after dropping the iteration pin, regardless of whether the file matched the predicate. Use nlm_file_inuse(), which does a live walk of the inode lock list, rather than the cached f_locks field, so skipped files that never ran nlm_inspect_file() are evaluated correctly. Because every file in a hash bucket is now pinned and released, files skipped by the is_failover_file predicate that have no locks, blocks, shares, or external references are deleted during traversal. The old code never evaluated skipped files for cleanup. The new behavior is intentional: such files are stale and should not persist in the table.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < e3c413f789eaf0170275c7eba523ead73d963f30 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < 08a455f87b14c7ff22ae3fdadda62a796a3a5572 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < 550c19222c7132c888e23c9d89079ba1c9bc4cca 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < 350087f231c11efcd288c310707c40eab63ca583 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < c24bdb7df2f34bdc38ca8a73796f5acb40f1830c 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < 41f0a6d31615fcae261bf28a0aa50050dc93a401 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < e999a88133654c6dfc68487fb49da5f20dfa2d4f 01df9c5e918ae5559f2d96da0143f8bfbb9e6171 < 526c49cff3f72c3ec74752016380c7567040581b
Linux / Linux
2.6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e3c413f789eaf0170275c7eba523ead73d963f30 git.kernel.org: https://git.kernel.org/stable/c/08a455f87b14c7ff22ae3fdadda62a796a3a5572 git.kernel.org: https://git.kernel.org/stable/c/550c19222c7132c888e23c9d89079ba1c9bc4cca git.kernel.org: https://git.kernel.org/stable/c/350087f231c11efcd288c310707c40eab63ca583 git.kernel.org: https://git.kernel.org/stable/c/c24bdb7df2f34bdc38ca8a73796f5acb40f1830c git.kernel.org: https://git.kernel.org/stable/c/41f0a6d31615fcae261bf28a0aa50050dc93a401 git.kernel.org: https://git.kernel.org/stable/c/e999a88133654c6dfc68487fb49da5f20dfa2d4f git.kernel.org: https://git.kernel.org/stable/c/526c49cff3f72c3ec74752016380c7567040581b