๐Ÿ” CVE Alert

CVE-2026-89712

CRITICAL 9.8

NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
a4bc287943f5695209ff36bdc89f17b48d68fae7 < 2b59029b8f24a99b5d844af2da3950d39d36eeea f4e44b393389c77958f7c58bf4415032b4cda15b < d9e151fea5ed706c1284adacabd869b0be745db2 f4e44b393389c77958f7c58bf4415032b4cda15b < 659ee3da073164e1e6e40dfcbc26eeed85845f93 f4e44b393389c77958f7c58bf4415032b4cda15b < 60680ae7243b22de3d09be990d8e23bcfc4af837 f4e44b393389c77958f7c58bf4415032b4cda15b < 77de363d9a1c8cd35f20482782c612cda085791a f4e44b393389c77958f7c58bf4415032b4cda15b < 4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8 f4e44b393389c77958f7c58bf4415032b4cda15b < 7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9 f4e44b393389c77958f7c58bf4415032b4cda15b < 036c1b182f4da65363e79ec0ac276edc6b7296e5 5.10.220 < 5.10.270
Linux / Linux
5.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2b59029b8f24a99b5d844af2da3950d39d36eeea git.kernel.org: https://git.kernel.org/stable/c/d9e151fea5ed706c1284adacabd869b0be745db2 git.kernel.org: https://git.kernel.org/stable/c/659ee3da073164e1e6e40dfcbc26eeed85845f93 git.kernel.org: https://git.kernel.org/stable/c/60680ae7243b22de3d09be990d8e23bcfc4af837 git.kernel.org: https://git.kernel.org/stable/c/77de363d9a1c8cd35f20482782c612cda085791a git.kernel.org: https://git.kernel.org/stable/c/4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8 git.kernel.org: https://git.kernel.org/stable/c/7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9 git.kernel.org: https://git.kernel.org/stable/c/036c1b182f4da65363e79ec0ac276edc6b7296e5