๐Ÿ” CVE Alert

CVE-2026-90037

UNKNOWN 0.0

NFSD: Prevent client use-after-free during close_lru reaping

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final CLOSE keeps its last closed stateid in oo_last_closed_stid, holding only a raw pointer to its nfs4_client. The laundromat reaps timed-out entries, drops nn->client_lock, and calls nfs4_put_stid(), which dereferences the client through cl_lock. Nothing pins the client across that window, so a concurrent force_expire_client() can free it and nfs4_put_stid() reads freed memory. __destroy_client() hits the same race, walking clp->cl_openowners without cl_lock. Pin the client with cl_rpc_users before dropping client_lock, and skip clients already expiring. __destroy_client() then cleans up its own close_lru entries through release_last_closed_stateid(), so teardown no longer races the laundromat.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
217526e7ecc9f6f243e976772e81eab7ab986a4c < 83dd59ac1c3455c2c7d8ddb582d980a13199b9b3 217526e7ecc9f6f243e976772e81eab7ab986a4c < e57a9ed34ea8c17e831de59b8f1a6b2d80d347a1 217526e7ecc9f6f243e976772e81eab7ab986a4c < 2330b788d732f43668b965b3105b37ceb276dfea
Linux / Linux
3.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/83dd59ac1c3455c2c7d8ddb582d980a13199b9b3 git.kernel.org: https://git.kernel.org/stable/c/e57a9ed34ea8c17e831de59b8f1a6b2d80d347a1 git.kernel.org: https://git.kernel.org/stable/c/2330b788d732f43668b965b3105b37ceb276dfea