PT-2026-93679 · Linux · Linux Kernel
CVE-2026-90038
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
nfsd4 revoke export states() function. The function drops the nn->client lock during the execution of revoke one stid() and the subsequent read of clp->cl minorversion, but the stateid reference does not pin the client. This allows a teardown process to race with the dropped lock and free the client while revoke one stid() is still dereferencing it. This path is triggered via NFSD CMD UNLOCK EXPORT when an administrator uses exportfs -u to remove an export, which can race with a client expiry.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel