PT-2026-94582 · Linux · Linux Kernel
CVE-2026-90234
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Network File System (NFS) implementation where the client fails to record a delegation granted by the server during an OPEN reply. Specifically, the
nfs inode set delegation() function contains three error flows that return without sending a DELEGRETURN. Because a delegation can only be relinquished via DELEGRETURN, the server incorrectly believes the client still holds the delegation. If the server attempts to recall it, the client responds with NFS4ERR BADHANDLE due to a missing stateid record. This leads the server to move the delegation to its cl revoked list. Consequently, subsequent SEQUENCE replies include SEQ4 STATUS RECALLABLE STATE REVOKED, causing the client's state manager to enter a loop issuing TEST STATEID across its delegations without resolving the condition.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel