CVE-2026-89688
Received Received - Intake

Use-After-Free in Linux Kernel NFS Server

Vulnerability report for CVE-2026-89688, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd4_cstate_assign_replay() returns -EAGAIN (the replay owner is being torn down, RP_UNHASHED) it has not taken a stateowner reference on that path. The error handling nevertheless called nfs4_put_stateowner(stp->st_stateowner), dropping an so_count reference the function never acquired -- risking a stateowner refcount underflow and use-after-free -- while leaking the sc_count reference held on the stid. The leaked stid reference can also stall a concurrent nfsd4_close_open_stateid() waiting for sc_count to drop. Drop the reference actually held -- the stid -- before retrying. The stateowner stays alive through the reference held by the stid. This mirrors the open path in nfsd4_process_open1(), where the put balances a reference that path explicitly holds on the stateowner.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect reference counting in the NFS server code. When handling a replay retry in nfs4_preprocess_seqid_op(), the code drops a reference to a stateowner object that was never acquired, leading to a potential use-after-free and reference count underflow. The stateid reference is leaked, which can stall other operations waiting for it to be released.

Detection Guidance

This vulnerability is specific to the Linux kernel's NFS server implementation and requires kernel-level inspection. Detection involves checking kernel logs for NFS-related errors or crashes, particularly during stateid operations. Commands like dmesg | grep nfsd or journalctl -k | grep nfsd may reveal issues. However, no direct detection commands are provided in the context.

Impact Analysis

This vulnerability could lead to system crashes, data corruption, or privilege escalation if exploited. It may cause instability in NFS services and potentially allow attackers to execute arbitrary code or gain unauthorized access to sensitive data.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it pertains to a Linux kernel NFS server issue involving stateid and stateowner reference handling. Compliance impacts would depend on system configuration and data exposure, which are not addressed in the provided CVE details.

Mitigation Strategies

Apply the latest Linux kernel security updates to patch this vulnerability. If immediate patching is not possible, consider disabling NFS server functionality temporarily or restricting NFS access to trusted networks until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89688. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart