{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89712","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.751Z","datePublished":"2026-09-11T19:46:27.018Z","dateUpdated":"2026-09-14T12:02:11.760Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:11.760Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock\n\nnfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with\nlist_for_each_entry_safe(ni, tmp, ...).  For each expired entry it\nsets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the\nsource vfsmount, then reacquires the lock to list_del + kfree the\nentry and continue iterating via the macro's saved tmp pointer.\n\nThe nsui_busy flag protects the current ni from concurrent\nnfsd4_ssc_setup_dul() finders during the lock-drop window, but it\ndoes not pin tmp.  Another nfsd RPC thread that fails its source-\nserver mount and reaches nfsd4_ssc_cancel_dul() will, during that\nsame window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount\nitem, and release the lock.  If that item is the saved tmp of the\nexpire walk, the next iteration dereferences a freed\nnfsd4_ssc_umount_item.\n\nRestart the walk from the head after the mntput() unlock window so\nno saved next pointer survives the lock-drop.  The list is bounded\nby the number of active inter-server source mounts (typically small)\nand the expire delayed-work runs periodically rather than per-IO,\nso the restart is cheap."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The UAF is between nfsd4_ssc_expire_umount() and nfsd4_ssc_cancel_dul(); cancel_dul runs from nfsd4_copy() on NFSv4.2 OP_COPY, reached by a COMPOUND over TCP/2049 to in-kernel nfsd. A remote client populates nfsd_ssc_mount_list and frees the saved iterator with no local access.\nAC:L - The attacker drives both race sides with concurrent async inter-server COPY requests: completed copies leave expired nfsd4_ssc_umount_item entries for the laundromat, while a COPY to another source IP fails vfs_kern_mount() into cancel_dul() during mntput(). An attacker-controlled source NFS server can stall unmount, so the window is attacker-created and retryable.\nPR:N - Under AUTH_SYS (default for typical NFS deployments) the server verifies no secret; EXCHANGE_ID, CREATE_SESSION, and OPEN succeed for any host allowed by the export, so no server-verified privileges are required to issue the COPY compounds that hit setup_dul/cancel_dul.\nUI:N - The attacker’s own NFS client issues the COPY compounds and source-server traffic that create, expire, and cancel ssc_umount items; no administrator or other user action on the victim server is required.\nS:U - The use-after-free is of a kmalloc’d nfsd4_ssc_umount_item in the nfsd host kernel; impact stays within the same kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - After cancel_dul() kfree()s the saved tmp, the expire walk continues from a freed nfsd4_ssc_umount_item whose vfsmount, list links, and metadata the attacker can replace via slab reuse, giving a UAF read primitive over kernel heap.\nI:H - The expire path then writes nsui_busy, calls mntput() on attacker-controlled nsui_vfsmount, and runs list_del()/kfree() on poisoned pointers, yielding arbitrary-write and control-flow hijack primitives from the same UAF.\nA:H - Dereferencing the freed list node in nfsd4_ssc_expire_umount() oopses or panics the laundromat worker even without a full exploit, taking down the in-kernel NFS server."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"a4bc287943f5695209ff36bdc89f17b48d68fae7","lessThan":"2b59029b8f24a99b5d844af2da3950d39d36eeea","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"d9e151fea5ed706c1284adacabd869b0be745db2","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"659ee3da073164e1e6e40dfcbc26eeed85845f93","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"60680ae7243b22de3d09be990d8e23bcfc4af837","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"77de363d9a1c8cd35f20482782c612cda085791a","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9","status":"affected","versionType":"git"},{"version":"f4e44b393389c77958f7c58bf4415032b4cda15b","lessThan":"036c1b182f4da65363e79ec0ac276edc6b7296e5","status":"affected","versionType":"git"},{"version":"5.10.220","lessThan":"5.10.270","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.220","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2b59029b8f24a99b5d844af2da3950d39d36eeea"},{"url":"https://git.kernel.org/stable/c/d9e151fea5ed706c1284adacabd869b0be745db2"},{"url":"https://git.kernel.org/stable/c/659ee3da073164e1e6e40dfcbc26eeed85845f93"},{"url":"https://git.kernel.org/stable/c/60680ae7243b22de3d09be990d8e23bcfc4af837"},{"url":"https://git.kernel.org/stable/c/77de363d9a1c8cd35f20482782c612cda085791a"},{"url":"https://git.kernel.org/stable/c/4ed8d2317aef21cc2a9e5a55d6b59860b4b151a8"},{"url":"https://git.kernel.org/stable/c/7377fa964b8aaf47cb04e5efcc4c82d15e8c2ce9"},{"url":"https://git.kernel.org/stable/c/036c1b182f4da65363e79ec0ac276edc6b7296e5"}],"title":"NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock","x_generator":{"engine":"bippy-1.2.0"}}}}