{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89658","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.743Z","datePublished":"2026-09-11T19:45:46.857Z","dateUpdated":"2026-09-13T06:32:40.908Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:40.908Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup\n\nnfs40_clean_admin_revoked() takes a stateid reference under\nclp->cl_lock, drops nn->client_lock, and calls\nnfsd4_drop_revoked_stid(), which dereferences the stateid's client\nthrough s->sc_client->cl_lock.  The stateid reference does not pin the\nclient, so a teardown racing the dropped lock can free the client\nwhile nfsd4_drop_revoked_stid() is still using it.\n\nThis cleanup runs from the laundromat, so a periodic sweep can race\nforce_expire_client() driven by a write to the clients/<id>/ctl file.\n\nSkip a client that is already expiring and otherwise pin it with\ncl_rpc_users under client_lock before dropping the lock, matching\nnfsd4_revoke_states()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The UAF is in nfsd NFSv4.0 revoked-state cleanup (nfs40_clean_admin_revoked). A remote peer reaches it over TCP/2049 via nfsd_dispatch to nfsd4_proc_compound: SETCLIENTID/SETCLIENTID_CONFIRM (ALLOWED_WITHOUT_FH) call expire_client() while the laundromat still uses the client.\nAC:L - The attacker controls the expire side by retrying SETCLIENTID_CONFIRM around the known lease interval, or by inducing the documented clients/<id>/ctl expire of a misbehaving client. Cleanup drops client_lock without pinning cl_rpc_users, so mark_client_expired_locked succeeds; this is not a race outside attacker influence.\nPR:N - OP_SETCLIENTID and OP_SETCLIENTID_CONFIRM are ALLOWED_WITHOUT_FH/ALLOWED_ON_ABSENT_FS with no export check. Typical nfsd AUTH_SYS/AUTH_NULL deployments never verify RPC credentials, so any host that can reach TCP/2049 can create NFSv4.0 state and trigger the expire.\nUI:N - The attacker drives the NFS compounds that establish state and expire the client. Administrative revoke or ctl expire is a server operational condition (unexport or response to a misbehaving client), not a required victim user action.\nS:U - The freed object is struct nfs4_client in the NFS server kernel. Impact remains in that kernel security authority; there is no VM, IOMMU, or sandbox boundary crossing.\nC:H - nfsd4_drop_revoked_stid() and nfs4_put_stid() dereference s->sc_client after expire_client() frees the nfs4_client. Reclaim of that slab lets an attacker groom contents and disclose kernel memory. Per kernel guidance a UAF is C:H.\nI:H - nfs4_put_stid() lock-and-idr_remove on the freed client's cl_lock/cl_stateids, concurrent with __destroy_client() list walks, is a slab UAF write primitive usable for heap corruption and control-flow hijacking. Per kernel guidance a UAF is I:H.\nA:H - Use of the freed nfs4_client spinlock, IDR, and lists oopses or panics the nfsd host, fully denying service of the NFS server."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"d688d8585e6bea5e4e37f7497feea93b6b0a469c","lessThan":"0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519","status":"affected","versionType":"git"},{"version":"d688d8585e6bea5e4e37f7497feea93b6b0a469c","lessThan":"b413ec5b23e3445dc9c4f273116078e2d4747626","status":"affected","versionType":"git"},{"version":"d688d8585e6bea5e4e37f7497feea93b6b0a469c","lessThan":"81cf7f1413862f87b078920c838460a6a88aa030","status":"affected","versionType":"git"},{"version":"d688d8585e6bea5e4e37f7497feea93b6b0a469c","lessThan":"7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519"},{"url":"https://git.kernel.org/stable/c/b413ec5b23e3445dc9c4f273116078e2d4747626"},{"url":"https://git.kernel.org/stable/c/81cf7f1413862f87b078920c838460a6a88aa030"},{"url":"https://git.kernel.org/stable/c/7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55"}],"title":"NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup","x_generator":{"engine":"bippy-1.2.0"}}}}