๐Ÿ” CVE Alert

CVE-2026-90151

UNKNOWN 0.0

NFSv4: remove callback IDR entry on client allocation failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later initialization step fails, the error path frees the nfs_client directly with nfs_free_client(). That bypasses nfs_put_client(), which is where the callback IDR entry is removed during normal teardown. A failed allocation can therefore leave cb_ident_idr pointing at a freed nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the stale pointer and take a reference to it. Make the callback IDR removal helper callable by the allocation failure path, and remove the callback identifier before freeing the client. This was found by a local static-analysis checker for publish-before-free lifetime bugs and confirmed by manual inspection.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 68c721391b761dbe38d5b0094d2bb6e8489ad92b f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 9bfdd0f591307b5198826a0e7a5b2f35f87acd2d f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 7c4812eb96bdcafb31a65b12f2aa96659429d1d4 f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < fc95ca82d5ae598c428ab5a00ae69f8526d59371 f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 80b1c3d5a881f7d9081aa9f46da9742878a0f893 f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 3f2387e8bfbc4efda5d77c3a11a028d0a119c48f f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < 5891c03e150920618db0e9c4ea2d772abacdcfd1 f4eecd5da3422e82e88e36c33cbd2595eebcacb1 < d05c2007b3d84ccba11dc6e9cb3202768cc72f14
Linux / Linux
2.6.38

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/68c721391b761dbe38d5b0094d2bb6e8489ad92b git.kernel.org: https://git.kernel.org/stable/c/9bfdd0f591307b5198826a0e7a5b2f35f87acd2d git.kernel.org: https://git.kernel.org/stable/c/7c4812eb96bdcafb31a65b12f2aa96659429d1d4 git.kernel.org: https://git.kernel.org/stable/c/fc95ca82d5ae598c428ab5a00ae69f8526d59371 git.kernel.org: https://git.kernel.org/stable/c/80b1c3d5a881f7d9081aa9f46da9742878a0f893 git.kernel.org: https://git.kernel.org/stable/c/3f2387e8bfbc4efda5d77c3a11a028d0a119c48f git.kernel.org: https://git.kernel.org/stable/c/5891c03e150920618db0e9c4ea2d772abacdcfd1 git.kernel.org: https://git.kernel.org/stable/c/d05c2007b3d84ccba11dc6e9cb3202768cc72f14