9.8

CVE-2026-89660

NFSD: Prevent client use-after-free during admin state revocation

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during admin state revocation

A stateid holds only a bare pointer to its nfs4_client; a stateid
reference does not pin it.  The client survives only because
__destroy_client() drains its stateids before free_client() runs.

nfsd4_revoke_states() drops nn->client_lock across revoke_one_stid(),
which dereferences the client to revoke a stateid and read
clp->cl_minorversion.  A teardown racing the dropped lock can free
the client first.

Pinning cl_rpc_users under client_lock blocks the DESTROY_CLIENTID and
EXCHANGE_ID teardown, which refuses while cl_rpc_users is non-zero.
force_expire_client() ignores it: once its wait for cl_rpc_users to
reach zero has passed, a later pin goes unnoticed.

Under client_lock, skip a client whose cl_time is already zero --
force_expire_client() clears it there before waiting -- otherwise pin
cl_rpc_users before dropping the lock.  The walk then either sees the
expiry and skips, or pins in time for that wait to cover the revoke.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc
Version < e1ba4d3c5bfdca3f013b8cbc829ae2f7975d8608
Status affected
Version 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc
Version < 549bd9868e9d77b07ea94870940d64342829c6ad
Status affected
Version 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc
Version < bf1f948691523282cc4905bc6cd325e0c0b49e6a
Status affected
Version 1c13bf9f2e3cd5a59ef988c6c5a49fe0f02bcdfc
Version < e270e5a0778e5bff852c8862ce9576ce70359393
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.463
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/549bd9868e9d77b07ea94870940d64342829c6ad
https://git.kernel.org/stable/c/bf1f948691523282cc4905bc6cd325e0c0b49e6a
https://git.kernel.org/stable/c/e270e5a0778e5bff852c8862ce9576ce70359393
https://git.kernel.org/stable/c/e1ba4d3c5bfdca3f013b8cbc829ae2f7975d8608