KernelScan.io

CRITICAL

nfsd RevokedDelegation UAF

CVE-2026-89703

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.3HIGH

01

In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked delegations but does not set SC_STATUS_FREED before releasing cl_lock. revoke_delegation() uses this flag to detect whether FREE_STATEID has already processed the delegation -- without it, the freed delegation is added to cl_revoked via list_add(), producing a use-after-free when cl_revoked is later traversed in __destroy_client(). The SC_STATUS_REVOKED path in nfsd4_free_stateid() (line 7983) already sets SC_STATUS_FREED correctly. Apply the same pattern to the SC_STATUS_ADMIN_REVOKED path in nfsd4_drop_revoked_stid().

02

Engine v0.6.0

Risk summary

An NFSv4 client can trigger a use-after-free in the kernel NFS server by sending a FREE_STATEID operation for an admin-revoked delegation during a race window with the server's laundromat thread. This can corrupt kernel heap memory, potentially leading to code execution or a kernel crash. Any system running nfsd with NFSv4 enabled and accessible to clients is at risk.

Affectedfs/nfsd/nfs4state.c (nfsd NFSv4 state management)

Vulnerability analysis

When an NFSv4 client sends FREE_STATEID for an admin-revoked delegation, the server frees the delegation object but fails to mark it as already freed before releasing the client lock. The laundromat thread, which handles expired delegation revocation, relies on this marker to skip delegations that FREE_STATEID has already processed. Without the flag, the laundromat adds the now-freed delegation back onto the revoked list, and when the client is later destroyed the kernel traverses that list and dereferences freed memory. The fix sets the freed flag before releasing the lock and freeing the object, matching the pattern already used for regular revoked delegations. Any authenticated NFSv4 client can trigger this by sending FREE_STATEID at the right moment during delegation revocation, requiring no special server-side privileges.

03

BranchIntroducedFixed inPatch commit
6.116.11.66.12d832a0587528
6.12—6.12.1091e4795766719
6.18—6.18.50a6d89032e5c6
7.2—7.2.4650d370cfbc6
mainline—7.3-rc1—