9.8

CVE-2026-89659

NFSD: Prevent client use-after-free during delegation revoke

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during delegation revoke

A delegation stateid holds only a bare pointer to its owning
nfs4_client and does not keep it alive.  The client survives its
stateids only because __destroy_client() drains cl_delegations and
cl_revoked before free_client() runs.

nfs4_laundromat() breaks that invariant: it unhashes an
expired delegation from cl_delegations, drops deleg_lock, then
revoke_delegation() relinks it onto cl_revoked under cl_lock.  In that
window the delegation is on neither list, so client_has_state() can
report no remaining state.

Every teardown path first requires cl_rpc_users to be zero, but
the laundromat holds no such reference.  A client whose recalled
delegation has just timed out can therefore reach free_client()
while revoke_delegation() is still about to dereference cl_lock,
a use-after-free.

Pin the client with cl_rpc_users across the revoke so teardown blocks
until it completes, then reap the delegation from cl_revoked.  A client
already expiring reaps its own, so skip it and leave the delegation on
del_recall_lru.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version < 0dd276b1324a5e08e83c6f675919946c9f0d61c9
Status affected
Version 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version < 3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3
Status affected
Version 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version < 2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56
Status affected
Version 3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version < 4683ca76b3b7e5808338491c6eb3c20e6b4894d5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.10
Status affected
Version 0
Version < 3.10
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.368
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3
https://git.kernel.org/stable/c/2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56
https://git.kernel.org/stable/c/4683ca76b3b7e5808338491c6eb3c20e6b4894d5
https://git.kernel.org/stable/c/0dd276b1324a5e08e83c6f675919946c9f0d61c9