KernelScan.io

CRITICAL Introduced in 3.10

nfsd Delegation UAF

CVE-2026-89659

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegation revoke A delegation stateid holds only a bare pointer to its owning nfs4_client and does not keep it alive. The client survives its stateids only because __destroy_client() drains cl_delegations and cl_revoked before free_client() runs. nfs4_laundromat() breaks that invariant: it unhashes an expired delegation from cl_delegations, drops deleg_lock, then revoke_delegation() relinks it onto cl_revoked under cl_lock. In that window the delegation is on neither list, so client_has_state() can report no remaining state. Every teardown path first requires cl_rpc_users to be zero, but the laundromat holds no such reference. A client whose recalled delegation has just timed out can therefore reach free_client() while revoke_delegation() is still about to dereference cl_lock, a use-after-free. Pin the client with cl_rpc_users across the revoke so teardown blocks until it completes, then reap the delegation from cl_revoked. A client already expiring reaps its own, so skip it and leave the delegation on del_recall_lru.

02

Engine v0.6.0

Risk summary

A remote NFS client can trigger a use-after-free in the kernel NFS server by holding a delegation until it expires, racing the server's laundromat revoke path against client teardown. Successful exploitation can corrupt kernel memory, leading to information disclosure, privilege escalation, or a kernel panic. Any system running NFSD with NFSv4 delegations enabled and reachable by NFS clients is affected.

Affectedfs/nfsd/nfs4state.c (nfsd)

Vulnerability analysis

The NFS server's background maintenance thread revokes expired delegations by first removing one from the client's active list and later moving it to the revoked list, but between those two steps the delegation is on neither list. During that window the server can incorrectly conclude the client has no remaining state and proceed to free the client structure while the revoke path is still about to access it, causing a use-after-free. The fix pins the client with a reference count before the delegation is removed, so any concurrent teardown blocks until the revoke completes and the delegation is safely on the revoked list; if the client is already expiring, the delegation is left for the client's own teardown to reap. Any NFS client that holds a delegation and lets it time out can trigger this race over the network against a server running NFSD with NFSv4 delegations enabled.

03

BranchIntroducedFixed inPatch commit
7.23.107.2.42a9d637c2a8f
6.183.106.18.513c0a53ee0b44
6.123.106.12.1110dd276b1324a
mainline3.107.3-rc14683ca76b3b7