Linux Kernel NFSd: NULL Dereference During Startup via NFSD_NET_UP
CVE-2026-90039 Published on September 16, 2026
NFSD: Guard admin state-revocation walks with NFSD_NET_UP
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Guard admin state-revocation walks with NFSD_NET_UP
Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,
walks the NFSv4 client hash tables to revoke open state and cancel
async COPY operations. All three handlers gate that walk on
nn->nfsd_serv, but a listener added via portlist or netlink
listener_set sets nn->nfsd_serv before any nfsd thread starts.
nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the
walkers dereference a NULL table. A local administrator with
CAP_SYS_ADMIN can crash the kernel this way without ever starting the
server.
nn->nfsd_serv is set when the service is created, which precedes
table allocation. NFSD_NET_UP instead brackets the window where the
tables are live: set at the end of nfsd_startup_net() and cleared in
nfsd_shutdown_net() after they are freed, both under nfsd_mutex.
Gating the three unlock paths on NFSD_NET_UP fixes the startup-time
NULL dereference while preserving the earlier post-shutdown
use-after-free fix.
Products Associated with CVE-2026-90039
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1ac3629bf012592cb0320e52a1cceb319a05ad17 and below 104a51265042b4424085741c963cb858ac29ec0b is affected.
- Version 1ac3629bf012592cb0320e52a1cceb319a05ad17 and below 0146467a2fce845cb6629979c3e9c58dd3d3a6a3 is affected.
- Version 1ac3629bf012592cb0320e52a1cceb319a05ad17 and below 2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378 is affected.
- Version 6.9 is affected.
- Before 6.9 is unaffected.
- Version 6.18.51, <= 6.18.* is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.