Use-After-Free Vulnerability in Linux Kernel Affects NFS Client Management
CVE-2026-90036

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90036?

A use-after-free vulnerability exists in the Linux kernel's NFS client management system. When a bare lock owner remains as the only reference during blocked-lock reaping, it can potentially lead to dereferencing freed memory. This occurs because the process may free the client before properly managing the lock references, which can cause security risks by allowing unauthorized access to invalid memory. The flaw has been addressed with updates that ensure proper locking mechanisms are in place to manage references correctly.

Affected Version(s)

Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b

Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 6fedb2eaff77554ca7a0deffd2e8bc0d6e8b38b0

Linux 7919d0a27f1e7cb324e023776aa1cbff00f1ee7b < 9026932ac8be4d0ae01db47f23619a98cc57b671

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.