CRITICAL Introduced in 6.9
nfsd StateRevoke UAF
CVE-2026-89660
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin state revocation A stateid holds only a bare pointer to its nfs4_client; a stateid reference does not pin it. The client survives only because __destroy_client() drains its stateids before free_client() runs. nfsd4_revoke_states() drops nn->client_lock across revoke_one_stid(), which dereferences the client to revoke a stateid and read clp->cl_minorversion. A teardown racing the dropped lock can free the client first. Pinning cl_rpc_users under client_lock blocks the DESTROY_CLIENTID and EXCHANGE_ID teardown, which refuses while cl_rpc_users is non-zero. force_expire_client() ignores it: once its wait for cl_rpc_users to reach zero has passed, a later pin goes unnoticed. Under client_lock, skip a client whose cl_time is already zero -- force_expire_client() clears it there before waiting -- otherwise pin cl_rpc_users before dropping the lock. The walk then either sees the expiry and skips, or pins in time for that wait to cover the revoke.
02KernelScan AI Analysis
Risk summary
A use-after-free in the NFS server's state revocation path can be triggered when a network NFS client races a teardown request against an administrator-initiated revocation operation. The vulnerability can lead to kernel memory corruption, potentially allowing a remote unprivileged NFS client to crash the server or escalate to arbitrary kernel read/write. Exploitation is difficult because it requires precise timing and the concurrent execution of an admin operation the attacker cannot initiate.
Vulnerability analysis
The NFS server's administrative state revocation routine drops a lock while it still holds an unpinned pointer to a client structure. A concurrent client teardown—triggered by the client over the network or by the server's own expiry mechanism—can free that structure before the revocation routine finishes using it, resulting in a use-after-free. The fix pins the client's reference count before dropping the lock and skips clients that are already being torn down, ensuring the structure stays alive for the duration of the revocation. A malicious NFS client with no special privileges can trigger the racing teardown path, but the revocation routine must be running concurrently—an administrator operation that the attacker cannot initiate themselves.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.9 | 6.12.111 | e1ba4d3c5bfd |
| 7.2 | 6.9 | 7.2.4 | bf1f94869152 |
| 6.18 | 6.9 | 6.18.51 | 549bd9868e9d |
| mainline | 6.9 | 7.3-rc1 | e270e5a0778e |