← All Advisories

CVE-2026-89660

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89660

Key Details

CVECVE-2026-89660
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Prevent client use-after-free during admin state revocation

A stateid holds only a bare pointer to its nfs4_client; a stateid

reference does not pin it. The client survives only because

__destroy_client() drains its stateids before free_client() runs.

nfsd4_revoke_states() drops nn->client_lock across revoke_one_stid(),

which dereferences the client to revoke a stateid and read

clp->cl_minorversion. A teardown racing the dropped lock can free

the client first.

Pinning cl_rpc_users under client_lock blocks the DESTROY_CLIENTID and

EXCHANGE_ID teardown, which refuses while cl_rpc_users is non-zero.

force_expire_client() ignores it: once its wait for cl_rpc_users to

reach zero has passed, a later pin goes unnoticed.

Under client_lock, skip a client whose cl_time is already zero --

force_expire_client() clears it there before waiting -- otherwise pin

cl_rpc_users before dropping the lock. The walk then either sees the

expiry and skips, or pins in time for that wait to cover the revoke. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89660
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89660