CRITICAL Introduced in 7.2
nfsd ExportState UAF
CVE-2026-90038
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.4MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export state revocation nfsd4_revoke_export_states() has the same use-after-free as nfsd4_revoke_states(): it drops nn->client_lock across revoke_one_stid() and the following read of clp->cl_minorversion, but the stateid reference it holds does not pin the client. A teardown racing the dropped lock can free the client while revoke_one_stid() still dereferences it. exportfs -u drives this path through NFSD_CMD_UNLOCK_EXPORT, so an administrator removing an export can race a client expiry. Skip a client that is already expiring and otherwise pin it with cl_rpc_users under client_lock before dropping the lock, matching nfsd4_revoke_states().
02KernelScan AI Analysis
Risk summary
A use-after-free in the NFS server's export state revocation path allows a client object to be freed while still being accessed when an administrator unexports a path and a client teardown races the operation. The bug requires root-level access to trigger via `exportfs -u` and winning a race window with client expiry. Successful exploitation can lead to kernel memory corruption, information disclosure, or a system crash.
Vulnerability analysis
When an administrator removes an NFS export, the NFS server revokes all NFSv4 state (opens, locks, delegations) tied to that export path. During this revocation the code iterates over clients, drops a global lock to process each stateid, and then reads a field from the client object after the lock is released — but the reference it holds is to the stateid, not to the client, so a concurrent client teardown can free the client in that window. The fix skips clients that are already expiring and pins the client with an extra reference count before the lock is dropped, releasing it only after the revocation work completes. This path is reachable only by a privileged administrator running `exportfs -u` on an active NFS server, and exploitation requires the admin action to race a client lease expiry.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 7.2 | 7.2.5 | c05ae58fe06c |
| mainline | 7.2 | 7.3-rc1 | 2108de53568a |