9.8
CVE-2026-89659
- EPSS 0.44%
- Veröffentlicht 11.09.2026 19:45:47
- Zuletzt bearbeitet 21.09.2026 14:17:24
- Erkennungen
NFSD: Prevent client use-after-free during delegation revoke
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client survives its stateids only because __destroy_client() drains cl_delegations and cl_revoked before free_client() runs. nfs4_laundromat() breaks that invariant: it unhashes an expired delegation from cl_delegations, drops deleg_lock, then revoke_delegation() relinks it onto cl_revoked under cl_lock. In that window the delegation is on neither list, so client_has_state() can report no remaining state. Every teardown path first requires cl_rpc_users to be zero, but the laundromat holds no such reference. A client whose recalled delegation has just timed out can therefore reach free_client() while revoke_delegation() is still about to dereference cl_lock, a use-after-free. Pin the client with cl_rpc_users across the revoke so teardown blocks until it completes, then reap the delegation from cl_revoked. A client already expiring reaps its own, so skip it and leave the delegation on del_recall_lru.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version <
0dd276b1324a5e08e83c6f675919946c9f0d61c9
Status
affected
Version
3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version <
3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3
Status
affected
Version
3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version <
2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56
Status
affected
Version
3bd64a5ba1719c2bb6cba4493dfd3e23a7653e54
Version <
4683ca76b3b7e5808338491c6eb3c20e6b4894d5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.10
Status
affected
Version
0
Version <
3.10
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.368 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/3c0a53ee0b442348d8d2286d6960d3f07bb3a3d3
https://git.kernel.org/stable/c/2a9d637c2a8fd8ac29ad9b29f28d122ef75c1a56
https://git.kernel.org/stable/c/4683ca76b3b7e5808338491c6eb3c20e6b4894d5
https://git.kernel.org/stable/c/0dd276b1324a5e08e83c6f675919946c9f0d61c9