PT-2026-93679 · Linux · Linux Kernel

CVE-2026-90038

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the nfsd4 revoke export states() function. The function drops the nn->client lock during the execution of revoke one stid() and the subsequent read of clp->cl minorversion, but the stateid reference does not pin the client. This allows a teardown process to race with the dropped lock and free the client while revoke one stid() is still dereferencing it. This path is triggered via NFSD CMD UNLOCK EXPORT when an administrator uses exportfs -u to remove an export, which can race with a client expiry.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90038
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel