← All Advisories

CVE-2026-90039

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90039

Key Details

CVECVE-2026-90039
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the

NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,

walks the NFSv4 client hash tables to revoke open state and cancel

async COPY operations. All three handlers gate that walk on

nn->nfsd_serv, but a listener added via portlist or netlink

listener_set sets nn->nfsd_serv before any nfsd thread starts.

nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the

walkers dereference a NULL table. A local administrator with

CAP_SYS_ADMIN can crash the kernel this way without ever starting the

server.

nn->nfsd_serv is set when the service is created, which precedes

table allocation. NFSD_NET_UP instead brackets the window where the

tables are live: set at the end of nfsd_startup_net() and cleared in

nfsd_shutdown_net() after they are freed, both under nfsd_mutex.

Gating the three unlock paths on NFSD_NET_UP fixes the startup-time

NULL dereference while preserving the earlier post-shutdown

use-after-free fix. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90039
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90039