KernelScan.io

CRITICAL Introduced in 3.17

nfsd CloseLru UAF

CVE-2026-90037

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final CLOSE keeps its last closed stateid in oo_last_closed_stid, holding only a raw pointer to its nfs4_client. The laundromat reaps timed-out entries, drops nn->client_lock, and calls nfs4_put_stid(), which dereferences the client through cl_lock. Nothing pins the client across that window, so a concurrent force_expire_client() can free it and nfs4_put_stid() reads freed memory. __destroy_client() hits the same race, walking clp->cl_openowners without cl_lock. Pin the client with cl_rpc_users before dropping client_lock, and skip clients already expiring. __destroy_client() then cleans up its own close_lru entries through release_last_closed_stateid(), so teardown no longer races the laundromat.

02

Engine v0.6.0

Risk summary

A use-after-free vulnerability in the Linux kernel's NFS server (nfsd) can be triggered by a remote NFS client through carefully timed file operations and lease expiration. Successful exploitation could lead to kernel memory corruption, potentially allowing code execution or a system crash. Any system running an NFS server exposed to network access is at risk.

Affectedfs/nfsd/nfs4state.c (nfsd)

Vulnerability analysis

The NFS server's periodic cleanup mechanism reaps expired entries from a close-tracking list, but drops a lock before releasing the associated state object, which still holds a raw pointer to the NFS client. During this unlocked window, a concurrent client expiration can free the client object, causing the cleanup to access freed memory. The fix pins the client by taking a reference count before the lock is dropped and skips clients already being torn down, and the client destruction path now cleans up its own close-list entries directly so it no longer races with the periodic cleanup. An attacker who can connect to the NFS server as a client can trigger this by performing open and close operations and timing lease expiration to coincide with the server's cleanup cycle.

03

BranchIntroducedFixed inPatch commit
mainline3.177.3-rc12330b788d732
6.123.176.12.111076348222782
6.183.176.18.5183dd59ac1c34
7.23.177.2.5e57a9ed34ea8