CVE-2026-90151
CVE CVE-2026-90151EUVD EUVD-2026-81744Published 2026-09-17T16:06:44.000ZLast changed 2026-09-18T17:53:26.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later initialization step fails, the error path frees the nfs_client directly with nfs_free_client(). That bypasses nfs_put_client(), which is where the callback IDR entry is removed during normal teardown. A failed allocation can therefore leave cb_ident_idr pointing at a freed nfs_client. A later NFSv4.0 callback lookup by cb_ident would find the stale pointer and take a reference to it. Make the callback IDR removal helper callable by the allocation failure path, and remove the callback identifier before freeing the client. This was found by a local static-analysis checker for publish-before-free lifetime bugs and confirmed by manual inspection.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <68c721391b761dbe38d5b0094d2bb6e8489ad92b; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <5891c03e150920618db0e9c4ea2d772abacdcfd1; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <fc95ca82d5ae598c428ab5a00ae69f8526d59371; patch: 5.15.221; patch: 7.3-rc1; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <80b1c3d5a881f7d9081aa9f46da9742878a0f893; patch: 5.10.270; patch: 0; patch: 6.6.157; patch: 7.2.6; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <7c4812eb96bdcafb31a65b12f2aa96659429d1d4; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <d05c2007b3d84ccba11dc6e9cb3202768cc72f14; patch: 6.1.188; patch: 6.12.110; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <3f2387e8bfbc4efda5d77c3a11a028d0a119c48f; f4eecd5da3422e82e88e36c33cbd2595eebcacb1 <9bfdd0f591307b5198826a0e7a5b2f35f87acd2d; 2.6.38; patch: 6.18.52
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.