Linux KRNL: NFSD Export State Revocation Use-After-Free
CVE-2026-90038 Published on September 16, 2026
NFSD: Prevent client use-after-free during export state revocation
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Prevent client use-after-free during export state revocation
nfsd4_revoke_export_states() has the same use-after-free as
nfsd4_revoke_states(): it drops nn->client_lock across
revoke_one_stid() and the following read of clp->cl_minorversion, but
the stateid reference it holds does not pin the client. A teardown
racing the dropped lock can free the client while revoke_one_stid()
still dereferences it.
exportfs -u drives this path through NFSD_CMD_UNLOCK_EXPORT, so an
administrator removing an export can race a client expiry.
Skip a client that is already expiring and otherwise pin it with
cl_rpc_users under client_lock before dropping the lock, matching
nfsd4_revoke_states().
Products Associated with CVE-2026-90038
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 2eac189bb059d31a29937b29ee0f477394198610 and below c05ae58fe06ce2ac34312f649e71c3596bdde358 is affected.
- Version 2eac189bb059d31a29937b29ee0f477394198610 and below 2108de53568a64936a0da3e04d85c35df98d3fb6 is affected.
- Version 7.2 is affected.
- Before 7.2 is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.