CVE-2026-90039
CVE CVE-2026-90039EUVD EUVD-2026-80647Published 2026-09-16T10:33:38.000ZLast changed 2026-09-21T13:15:14.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_NET_UP Writing to /proc/fs/nfsd/unlock_filesystem, or sending the NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command, walks the NFSv4 client hash tables to revoke open state and cancel async COPY operations. All three handlers gate that walk on nn->nfsd_serv, but a listener added via portlist or netlink listener_set sets nn->nfsd_serv before any nfsd thread starts. nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the walkers dereference a NULL table. A local administrator with CAP_SYS_ADMIN can crash the kernel this way without ever starting the server. nn->nfsd_serv is set when the service is created, which precedes table allocation. NFSD_NET_UP instead brackets the window where the tables are live: set at the end of nfsd_startup_net() and cleared in nfsd_shutdown_net() after they are freed, both under nfsd_mutex. Gating the three unlock paths on NFSD_NET_UP fixes the startup-time NULL dereference while preserving the earlier post-shutdown use-after-free fix.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.12.111; 6.9; 1ac3629bf012592cb0320e52a1cceb319a05ad17 <0146467a2fce845cb6629979c3e9c58dd3d3a6a3; patch: 7.3-rc1; patch: 6.18.51; patch: 0; patch: 7.2.5; 1ac3629bf012592cb0320e52a1cceb319a05ad17 <104a51265042b4424085741c963cb858ac29ec0b; 1ac3629bf012592cb0320e52a1cceb319a05ad17 <2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378; 1ac3629bf012592cb0320e52a1cceb319a05ad17 <73bf459d696ecf207a9037bf9bb70c51a459469e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.