๐Ÿ” CVE Alert

CVE-2026-89660

CRITICAL 9.8

NFSD: Prevent client use-after-free during admin state revocation

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The client survives only because __destroy_client() drains its stateids before free_client() runs. nfsd4_revoke_states() drops nn->client_lock across revoke_one_stid(), which dereferences the client to revoke a stateid and read clp->cl_minorversion. A teardown racing the dropped lock can free the client first. Pinning cl_rpc_users under client_lock blocks the DESTROY_CLIENTID and EXCHANGE_ID teardown, which refuses while cl_rpc_users is non-zero. force_expire_client() ignores it: once its wait for cl_rpc_users to reach zero has passed, a later pin goes unnoticed. Under client_lock, skip a client whose cl_time is already zero -- force_expire_client() clears it there before waiting -- otherwise pin cl_rpc_users before dropping the lock. The walk then either sees the expiry and skips, or pins in time for that wait to cover the revoke.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc < 549bd9868e9d77b07ea94870940d64342829c6ad 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc < bf1f948691523282cc4905bc6cd325e0c0b49e6a 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc < e270e5a0778e5bff852c8862ce9576ce70359393
Linux / Linux
6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/549bd9868e9d77b07ea94870940d64342829c6ad git.kernel.org: https://git.kernel.org/stable/c/bf1f948691523282cc4905bc6cd325e0c0b49e6a git.kernel.org: https://git.kernel.org/stable/c/e270e5a0778e5bff852c8862ce9576ce70359393