CVE-2026-89485
Received Received - Intake

Use-After-Free in Linux Kernel lockd Subsystem

Vulnerability report for CVE-2026-89485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved next pointer. A concurrent nlm_release_file() can kfree the next file during the unlock window, and the iterator dereferences freed memory on the next loop step. Pin both current and next before the lock-drop. Advance by swapping the pinned cursors at the end of each iteration so next is always held alive across the unlock. Always call nlm_file_release() after dropping the iteration pin, regardless of whether the file matched the predicate. Use nlm_file_inuse(), which does a live walk of the inode lock list, rather than the cached f_locks field, so skipped files that never ran nlm_inspect_file() are evaluated correctly. Because every file in a hash bucket is now pinned and released, files skipped by the is_failover_file predicate that have no locks, blocks, shares, or external references are deleted during traversal. The old code never evaluated skipped files for cleanup. The new behavior is intentional: such files are stale and should not persist in the table.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the lockd component. The issue occurs when traversing files while holding a lock. The iterator pins the current file but not the next file pointer. A concurrent operation can free the next file during a lock drop, leading to a use-after-free when the iterator tries to access it.

Detection Guidance

This vulnerability is specific to the Linux kernel's lockd subsystem and involves memory corruption due to improper file pinning during traversal. Detection requires checking kernel logs for lockd-related errors or kernel panics. Commands like dmesg | grep lockd or journalctl -k | grep lockd may reveal issues. Ensure your kernel version is updated to a patched release.

Impact Analysis

This vulnerability could allow an attacker to cause a denial-of-service by crashing the system or potentially execute arbitrary code with kernel privileges. It may lead to system instability, data corruption, or unauthorized access depending on the attacker's capabilities and system configuration.

Compliance Impact

This vulnerability is a memory management issue in the Linux kernel's lockd subsystem that could lead to use-after-free errors. It does not directly affect compliance with standards like GDPR or HIPAA, as those focus on data protection, privacy, and security controls rather than kernel memory management flaws.

Mitigation Strategies

Update the Linux kernel to the latest stable version that includes the fix for CVE-2026-89485. Reboot the system after applying the update. Monitor lockd operations and system stability post-update. If immediate patching is not possible, consider disabling lockd services temporarily if they are not critical.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart