{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89485","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.712Z","datePublished":"2026-09-11T19:43:39.403Z","dateUpdated":"2026-09-14T12:00:21.375Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:21.375Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: pin next file across nlm_inspect_file lock-drop\n\nnlm_traverse_files() pins the current file with f_count++ across\na mutex_unlock for nlm_inspect_file(), but nothing pins the saved\nnext pointer.  A concurrent nlm_release_file() can kfree the next\nfile during the unlock window, and the iterator dereferences freed\nmemory on the next loop step.\n\nPin both current and next before the lock-drop.  Advance by\nswapping the pinned cursors at the end of each iteration so next\nis always held alive across the unlock.\n\nAlways call nlm_file_release() after dropping the iteration pin,\nregardless of whether the file matched the predicate.  Use\nnlm_file_inuse(), which does a live walk of the inode lock list,\nrather than the cached f_locks field, so skipped files that never\nran nlm_inspect_file() are evaluated correctly.\n\nBecause every file in a hash bucket is now pinned and released,\nfiles skipped by the is_failover_file predicate that have no\nlocks, blocks, shares, or external references are deleted during\ntraversal.  The old code never evaluated skipped files for\ncleanup.  The new behavior is intentional: such files are stale\nand should not persist in the table."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - lockd is the in-kernel NLM RPC server on TCP/UDP, reached by remote NFSv3 clients. nlm_traverse_files() runs on NLMPROC_FREE_ALL, and nlm_release_file() runs from LOCK/UNLOCK/TEST and from rpciod NLM_GRANTED_MSG completion, so the UAF is triggered by network NLM traffic.\nAC:L - A remote NFS client can populate nlm_files via LOCK, send FREE_ALL to drop nlm_file_mutex inside nlm_traverse_files(), and concurrently complete in-flight GRANTED_MSG callbacks so rpciod's nlmsvc_grant_release() calls nlm_release_file() on the unpinned next object; the attacker drives both sides of the race.\nPR:N - lockd_authenticate() accepts RPC_AUTH_NULL and RPC_AUTH_UNIX. FREE_ALL is not a privileged-port callback, and nlm_fopen() opens files with NFSD_MAY_BYPASS_GSS|NFSD_MAY_NLM, so no host account or capability is required.\nUI:N - Exploitation uses only attacker-sent NLM RPCs (LOCK/FREE_ALL and grant-callback completion); no victim user or administrator action is required.\nS:U - The use-after-free is in the host kernel's lockd file table and impacts that same kernel; it does not cross a VM, IOMMU, or other security-authority boundary.\nC:H - The iterator dereferences a kfree'd struct nlm_file (list pointers, f_file[], f_count). This UAF lets an attacker reuse the slab object and obtain a kernel read primitive, so confidentiality impact is high.\nI:H - The same nlm_file UAF is a kernel heap free of list nodes, mutex state, and struct file pointers, which can be sprayed for an arbitrary write and control-flow hijack, so integrity impact is high.\nA:H - Walking the freed nlm_file in nlm_traverse_files() causes a kernel oops/panic (KASAN slab-use-after-free), so availability impact is high."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/lockd/svcsubs.c"],"versions":[{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"e3c413f789eaf0170275c7eba523ead73d963f30","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"08a455f87b14c7ff22ae3fdadda62a796a3a5572","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"550c19222c7132c888e23c9d89079ba1c9bc4cca","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"350087f231c11efcd288c310707c40eab63ca583","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"c24bdb7df2f34bdc38ca8a73796f5acb40f1830c","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"41f0a6d31615fcae261bf28a0aa50050dc93a401","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"e999a88133654c6dfc68487fb49da5f20dfa2d4f","status":"affected","versionType":"git"},{"version":"01df9c5e918ae5559f2d96da0143f8bfbb9e6171","lessThan":"526c49cff3f72c3ec74752016380c7567040581b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/lockd/svcsubs.c"],"versions":[{"version":"2.6.18","status":"affected"},{"version":"0","lessThan":"2.6.18","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e3c413f789eaf0170275c7eba523ead73d963f30"},{"url":"https://git.kernel.org/stable/c/08a455f87b14c7ff22ae3fdadda62a796a3a5572"},{"url":"https://git.kernel.org/stable/c/550c19222c7132c888e23c9d89079ba1c9bc4cca"},{"url":"https://git.kernel.org/stable/c/350087f231c11efcd288c310707c40eab63ca583"},{"url":"https://git.kernel.org/stable/c/c24bdb7df2f34bdc38ca8a73796f5acb40f1830c"},{"url":"https://git.kernel.org/stable/c/41f0a6d31615fcae261bf28a0aa50050dc93a401"},{"url":"https://git.kernel.org/stable/c/e999a88133654c6dfc68487fb49da5f20dfa2d4f"},{"url":"https://git.kernel.org/stable/c/526c49cff3f72c3ec74752016380c7567040581b"}],"title":"lockd: pin next file across nlm_inspect_file lock-drop","x_generator":{"engine":"bippy-1.2.0"}}}}