CVE-2026-89658

Summary

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup

nfs40_clean_admin_revoked() takes a stateid reference under clp->cl_lock, drops nn->client_lock, and calls nfsd4_drop_revoked_stid(), which dereferences the stateid's client through s->sc_client->cl_lock. The stateid reference does not pin the client, so a teardown racing the dropped lock can free the client while nfsd4_drop_revoked_stid() is still using it.

This cleanup runs from the laundromat, so a periodic sweep can race force_expire_client() driven by a write to the clients/<id>/ctl file.

Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd688d8585e6bea5e4e37f7497feea93b6b0a469c < 0ae0d2b5c5a1b39c0b3c15d96b32a5b0c583d519affected
LinuxLinuxd688d8585e6bea5e4e37f7497feea93b6b0a469c < b413ec5b23e3445dc9c4f273116078e2d4747626affected
LinuxLinuxd688d8585e6bea5e4e37f7497feea93b6b0a469c < 81cf7f1413862f87b078920c838460a6a88aa030affected
LinuxLinuxd688d8585e6bea5e4e37f7497feea93b6b0a469c < 7b4f8a1586c42d3afc3c0ac779af2db7ab1a5c55affected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References