{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90036","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.782Z","datePublished":"2026-09-16T10:33:35.967Z","dateUpdated":"2026-09-21T13:15:12.107Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:15:12.107Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent client use-after-free during blocked-lock reaping\n\nA bare lock owner -- its only remaining reference a blocked lock on\nnn->blocked_locks_lru -- holds a raw pointer to its nfs4_client but\nno reference keeping the client alive. When the per-net laundromat\nreaps such a lock, freeing the nbl drops the owner reference\nheld through flc_owner, and the final nfs4_put_stateowner()\ntakes the client's cl_lock. Because the laundromat detaches the\nnbl first, __destroy_client() no longer finds it, so a concurrent\nforce_expire_client() can free the client before nfs4_put_stateowner()\nruns, dereferencing cl_lock in freed memory.\n\nPin the client with cl_rpc_users before dropping\nnn->blocked_locks_lock, and skip clients already expiring, whose\nblocked locks __destroy_client() frees while holding an owner\nreference. Take nn->client_lock outside nn->blocked_locks_lock.\nEvery other site holds nn->blocked_locks_lock as a leaf, acquiring\nno further lock, so placing nn->client_lock outside it cannot form\na lock-order cycle."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - NFSD is the in-kernel NFS server; the UAF is reached by remote NFSv4.1 COMPOUND RPCs over TCP/UDP 2049 (EXCHANGE_ID, CREATE_SESSION, OPEN, blocking LOCK, DESTROY_SESSION, DESTROY_CLIENTID) that queue a blocked lock and expire the client while nfs4_laundromat() reaps it.\nAC:L - The attacker controls both sides: one client holds a conflicting lock while another queues a FILE_LOCK_DEFERRED blocked lock (bare lockowner), then DESTROY_CLIENTID races with laundromat free_blocked_lock() after nbl detach; concurrent compounds create the race and it is retryable.\nPR:N - Typical nfsd deployments use AUTH_SYS/AUTH_NULL with no cryptographic RPC authentication. A remote peer that can reach an export can create NFSv4.1 state and issue DESTROY_CLIENTID (ALLOWED_WITHOUT_FH) without a local account or kernel capabilities on the server.\nUI:N - Exploitation requires only attacker-sent NFS RPCs against a running nfsd export. No victim user action such as mounting a filesystem or opening a local file on the server is required.\nS:U - The use-after-free is of struct nfs4_client in the NFS server kernel and does not cross a separate security authority such as a VM, guest/host, sandbox, or IOMMU boundary.\nC:H - free_blocked_lock() drops flc_owner into nfs4_put_stateowner(), which takes cl_lock on a nfs4_client already freed by concurrent expire_client(). The mergeable client_slab object (KMEM_CACHE flags 0) can be reclaimed via EXCHANGE_ID to disclose kernel memory.\nI:H - nfs4_put_stateowner() does atomic_dec_and_lock on the freed client's cl_lock and so_unhash walks client-owned lists; reclaiming the nfs4_client slab enables heap corruption and control-flow hijack. Kernel guidance scores use-after-free as I:H.\nA:H - Use-after-free of nfs4_client (spin_lock of freed cl_lock) in the laundromat worker oopses or panics the NFS server even without full exploitation, fully denying service of the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"7919d0a27f1e7cb324e023776aa1cbff00f1ee7b","lessThan":"7081224a59a0ca4edcd62c068588f4d900199a18","status":"affected","versionType":"git"},{"version":"7919d0a27f1e7cb324e023776aa1cbff00f1ee7b","lessThan":"cd489b03587378645fe0d20142a33f1ed60bac98","status":"affected","versionType":"git"},{"version":"7919d0a27f1e7cb324e023776aa1cbff00f1ee7b","lessThan":"6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0","status":"affected","versionType":"git"},{"version":"7919d0a27f1e7cb324e023776aa1cbff00f1ee7b","lessThan":"9026932ac8be4d0ae01db47f23619a98cc57b671","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfsd/nfs4state.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7081224a59a0ca4edcd62c068588f4d900199a18"},{"url":"https://git.kernel.org/stable/c/cd489b03587378645fe0d20142a33f1ed60bac98"},{"url":"https://git.kernel.org/stable/c/6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0"},{"url":"https://git.kernel.org/stable/c/9026932ac8be4d0ae01db47f23619a98cc57b671"}],"title":"NFSD: Prevent client use-after-free during blocked-lock reaping","x_generator":{"engine":"bippy-1.2.0"}}}}