CRITICAL
nfsd SSCUmount UAF
CVE-2026-89712
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.
02KernelScan AI Analysis
Risk summary
An NFS client that can issue NFSv4 inter-server copy operations to a vulnerable NFS server can trigger a use-after-free in the server's delayed unmount expire worker by racing a source-server mount failure with the periodic expire walk. Successful exploitation can corrupt kernel heap memory, potentially leading to code execution or a kernel panic. Any deployment exposing the NFS server to network clients with copy privileges is at risk.
Vulnerability analysis
The NFS server's delayed-unmount expire worker walks a list of inter-server copy source mounts, saving a pointer to the next entry before dropping its lock to release the current mount. During that lock-drop window, a concurrent NFS request that fails a source-server mount can remove and free that saved next entry; when the expire walk resumes and follows the stale pointer, it dereferences freed memory. The fix restarts the list walk from the head after every lock-drop window so that no saved next pointer survives across it, eliminating the dangling reference. An attacker who can send NFSv4 inter-server copy requests to the server — and whose source-server mount attempts fail in a way that races with the periodic expire worker — can reach this code path over the network without any special kernel privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | — | 7.3-rc1 | 036c1b182f4d |
| 5.10 | 5.10.220 | 5.10.270 | 2b59029b8f24 |
| 6.18 | — | 6.18.50 | 4ed8d2317aef |
| 5.15 | — | 5.15.221 | d9e151fea5ed |
| 6.6 | — | 6.6.157 | 60680ae7243b |
| 6.1 | — | 6.1.188 | 659ee3da0731 |
| 7.2 | — | 7.2.4 | 7377fa964b8a |
| 6.12 | — | 6.12.109 | 77de363d9a1c |