KernelScan.io

CRITICAL

nfsd SSCUmount UAF

CVE-2026-89712

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.

02

Engine v0.6.0

Risk summary

An NFS client that can issue NFSv4 inter-server copy operations to a vulnerable NFS server can trigger a use-after-free in the server's delayed unmount expire worker by racing a source-server mount failure with the periodic expire walk. Successful exploitation can corrupt kernel heap memory, potentially leading to code execution or a kernel panic. Any deployment exposing the NFS server to network clients with copy privileges is at risk.

Affectedfs/nfsd/nfs4state.c (nfsd)

Vulnerability analysis

The NFS server's delayed-unmount expire worker walks a list of inter-server copy source mounts, saving a pointer to the next entry before dropping its lock to release the current mount. During that lock-drop window, a concurrent NFS request that fails a source-server mount can remove and free that saved next entry; when the expire walk resumes and follows the stale pointer, it dereferences freed memory. The fix restarts the list walk from the head after every lock-drop window so that no saved next pointer survives across it, eliminating the dangling reference. An attacker who can send NFSv4 inter-server copy requests to the server — and whose source-server mount attempts fail in a way that races with the periodic expire worker — can reach this code path over the network without any special kernel privileges.

03

BranchIntroducedFixed inPatch commit
mainline—7.3-rc1036c1b182f4d
5.105.10.2205.10.2702b59029b8f24
6.18—6.18.504ed8d2317aef
5.15—5.15.221d9e151fea5ed
6.6—6.6.15760680ae7243b
6.1—6.1.188659ee3da0731
7.2—7.2.47377fa964b8a
6.12—6.12.10977de363d9a1c