CRITICAL Introduced in 2.6.38
nfs CallbackIdent UAF
CVE-2026-90151
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.4MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later initialization step fails, the error path frees the nfs_client directly with nfs_free_client(). That bypasses nfs_put_client(), which is where the callback IDR entry is removed during normal teardown. A failed allocation can therefore leave cb_ident_idr pointing at a freed nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the stale pointer and take a reference to it. Make the callback IDR removal helper callable by the allocation failure path, and remove the callback identifier before freeing the client. This was found by a local static-analysis checker for publish-before-free lifetime bugs and confirmed by manual inspection.
02KernelScan AI Analysis
Risk summary
A failed NFSv4 client allocation can leave a stale callback identifier pointer in a shared lookup table. A later NFSv4.0 callback lookup can find and take a reference to the freed client, leading to use-after-free. A local attacker with root privileges who can trigger NFSv4 mount operations can exploit this to corrupt kernel memory, potentially escalating privileges or crashing the system.
Vulnerability analysis
During NFSv4 client setup, a callback identifier is inserted into a shared kernel lookup table before all initialization steps finish. If a later setup step fails, the error path frees the client object directly without deleting that table entry, leaving a dangling pointer. A later NFSv4.0 callback lookup can find that stale pointer and take a reference to the freed memory. The fix makes the table cleanup available to the failure path and removes the identifier before freeing the client, so no stale pointer remains. Reaching the bug requires a local actor with root privileges who can initiate an NFSv4 mount.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.38 | 5.10.270 | 68c721391b76 |
| 5.15 | 2.6.38 | 5.15.221 | 9bfdd0f59130 |
| 6.1 | 2.6.38 | 6.1.188 | 7c4812eb96bd |
| 6.6 | 2.6.38 | 6.6.157 | fc95ca82d5ae |
| 7.2 | 2.6.38 | 7.2.6 | 5891c03e1509 |
| mainline | 2.6.38 | 7.3-rc1 | d05c2007b3d8 |
| 6.18 | 2.6.38 | 6.18.52 | 3f2387e8bfbc |
| 6.12 | 2.6.38 | 6.12.110 | 80b1c3d5a881 |